Type above and press Enter to search. Press Esc to cancel.

Loading...
Close Menu
  • Biology
  • Chemistry
  • Earth
  • Health
  • Physics
  • Science
  • Space
  • Technology
Facebook X (Twitter) Instagram

Quantumis

  • Biology
  • Chemistry
  • Earth
  • Health
  • Physics
  • Science
  • Space
  • Technology
Facebook X (Twitter) Pinterest YouTube
Quantumis
Home » » Mullvad VPN audit: low number of vulnerabilities found and fixed, lots of praise

Mullvad VPN audit: low number of vulnerabilities found and fixed, lots of praise

Facebook Twitter Pinterest Telegram LinkedIn WhatsApp Email Reddit
Share
Facebook Twitter LinkedIn Pinterest Telegram Email Reddit

Mullvad VPN is a popular privacy-focused VPN service. The service is using a disk-less infrastructure and has recently started to run encrypted DNS servers in RAM as well. You may also buy Mullvad codes on Amazon or through other ways that keep you anonymous.

In late 2024, Mullvad asked Germany-based X41 D-Sec to conduct an audit of the service, making it the fourth external security audit since 2018.

Company engineers were tasked with auditing the source code of Mullvad's VPN apps on all platforms and performing penetration testing. This happend between October and November 2024.

Vulnerabilities were found

X41 D-Sec discovered a total of six vulnerabilities.

  • Three high-security vulnerabilities.
  • Two medium-rated vulnerabilities.
  • One low vulnerability.

Additionally, the researches found three issues with security impact.

Mullvad addressed the issues that were within scope. Some of the discovered issues are not fixable by Mullvad, as they are found in certain behaviors of operating systems or protocols.

The three security issues rated high are all fixed. They were:

  • A potential heap corruption issue on Android, Linux, and macOS.
  • An issue with the fault signal handler in mullvad-daemon affecting Android, Linux, and macOS.
  • Use of taskkill.exe on Windows in the installer without use of absolute paths.

Not all issues can be fixed by Mullvad

One issue, rated medium, for instance, which may leak the virtual IP address of tunnel devices to network adjacent participants, affects Linux and Android only. On Linux, Mullvad solved the issue by changing a kernel parameter.

On Android, Mullvad's app has no control over that parameter. The company did report the issue to Google, hoping that Google will change the default behavior on Android to address this.

It should be noted that the issue affects other apps on Android as well. Mullvad says that it does not consider the leak high severity. It may however leak the tunnel IP to observers. IPs get changed monthly, but signing out of the app and back in again gives the client a new tunnel IP address as well.

Closing Words

Security audits find potential vulnerabilities, which companies may then fix proactively. They may also help instill confidence in existing or future users of the service, especially if conducted regularly.

Now it is your turn. Do you us a VPN solution? If so which and why? Feel free to leave a comment down below.

 

Share. Facebook Twitter Pinterest LinkedIn Email Reddit

Related Articles

Windows Utility WinUtil is a one-stop shop to customize Windows

iOS 18 has been released, here are the best new features in it

How to upgrade to Windows 11 24H2 on unsupported hardware

Rufus 4.6 bypasses Windows 11 24H2 compatibility checks automatically

Firefox adds option to remove 'List All Tabs' button after user backlash

How to enable Tab Groups in Firefox

How to enable the Ultimate Performance plan in Windows 11

VLC to add support for offline AI subtitles and translations

Customize ChatGPT to generate personalized responses based on your interests, profession

Wine 10.0 launches with enhanced compatibility for Windows apps on Linux

Comment

Leave A Reply Cancel Reply

Trending News

YouTube's server-side ads resulted in a black screen for ad blocker users

Windows 10 Start Menu will soon display ads for Microsoft 365

Windows 11 AI features are coming to Intel PCs this November

iOS 18 has been released, here are the best new features in it

YouTube Premium: another massive price increase in some regions angers users

Firefox adds option to remove 'List All Tabs' button after user backlash

Apple releases iOS 18.1, macOS 15.1 and iPadOS 18.1 with Apple Intelligence

Windows 11: Microsoft is finally adding an option to turn off one of the most annoying things

Mullvad VPN audit: low number of vulnerabilities found and fixed, lots of praise

How to rebuild the icon cache in Windows 11

Follow Quantumis
  • Facebook
  • Twitter
  • YouTube
  • Pinterest
SciTech News
  • Biology News
  • Chemistry News
  • Earth News
  • Health News
  • Physics News
  • Science News
  • Space News
  • Technology News
Recent Posts
  • Thunderbird 128 Upgrades are now enabled
  • Windows 10 Start Menu will soon display ads for Microsoft 365
  • Firefox 130: Translate improvements, automatic Picture-in-Picture mode, and security fixes
  • iOS 18.0.1 fixes iPhone touch screen problems and performance issues
  • How to upgrade to Windows 11 24H2 on unsupported hardware
  • Windows 11: issue may prevent further installations of updates
Copyright © 2025 Quantumis. All Rights Reserved.
  • About
  • Contact
  • Privacy Policy
  • Terms of Use