Original Research 8 min read

TunnelVision, TunnelCrack and Other Attacks on the VPN Tunnel, Explained

TunnelVision, TunnelCrack, port shadow and blind in/on-path attacks leak or hijack VPN traffic without breaking encryption. Who is at risk and how to defend.

TunnelVision, TunnelCrack and Other Attacks on the VPN Tunnel, Explained

Key Findings

  • TunnelVision (CVE-2024-3661, CVSS 7.6) lets an attacker on the same local network use DHCP option 121 to route traffic outside a VPN tunnel on Windows, Linux, macOS and iOS; Android is not affected because it does not implement that option.
  • TunnelCrack researchers tested more than 66 VPNs on five platforms in 2023 and found every iOS VPN app and all but one macOS client vulnerable to the LocalNet attack, versus about one-quarter of Android apps.
  • The port shadow flaw (CVE-2021-3773), rated 9.8 by NVD, lets another user of the same VPN server act as a router between a victim and the server; the researchers report Linux kernel fixes were attempted and then reverted.
  • None of these attacks decrypt VPN traffic; they trick the device or server into sending traffic outside the tunnel or into the attacker's path.
  • In TunnelVision, a VPN kill switch does not trigger because the VPN connection itself stays up, according to the researchers at Leviathan Security Group.

TunnelVision, TunnelCrack and related research attacks leave VPN encryption intact. They manipulate routing tables, DHCP settings or connection tracking so that some or all of your traffic travels outside the encrypted tunnel, or so that an attacker can insert themselves into it. Most require the attacker to control or share your local network, such as a public Wi-Fi hotspot, and the best defenses are VPN clients that firewall all non-tunnel traffic plus prompt updates.

Why “routing-based” VPNs can leak

A typical VPN app works by adding routes to your operating system so that internet-bound traffic goes to a virtual network interface, where it is encrypted and sent to the VPN server. The encryption is strong; the weak point is the routing decision that comes before it. If an attacker can convince your device that a destination is “local,” or that a more specific route exists, the operating system may send that traffic out of the normal Wi-Fi interface in plaintext.

TunnelVision and TunnelCrack both exploit that routing decision. A second family of attacks targets how operating systems track connections, which can let an attacker infer or tamper with tunneled connections without seeing their contents.

The attacks at a glance

CVSS scores are NIST NVD base scores (version 3.x). Higher is more severe.

AttackYear disclosedCVE (NVD CVSS)Attacker position neededMost affectedSource
IPv6 leakage and DNS hijacking2015NoneLocal networkMost of 14 commercial VPN services studied leaked IPv6 trafficPerta et al., 2015
Inferring and hijacking VPN-tunneled TCP connections2019CVE-2019-14899 (7.4)Malicious access point or adjacent userLinux, FreeBSD, OpenBSD, macOS, iOS, AndroidNVD
TunnelCrack: LocalNet2023CVE-2023-36672 (5.7), CVE-2023-35838 (5.7)Malicious Wi-Fi or Ethernet networkiOS, macOS, most Windows clientsTunnelCrack, 2023
TunnelCrack: ServerIP2023CVE-2023-36673 (7.3), CVE-2023-36671 (6.3)Malicious Wi-Fi or ISP able to spoof DNSBuilt-in clients on Windows, macOS, iOSTunnelCrack, 2023
TunnelVision2024CVE-2024-3661 (7.6)Rogue DHCP server on the same local networkWindows, Linux, macOS, iOSLeviathan, 2024; NVD
Port shadow2024 (paper)CVE-2021-3773 (9.8)Another user connected to the same VPN serverLinux and FreeBSD VPN serversCitizen Lab, 2024

TunnelVision (CVE-2024-3661)

Disclosed in May 2024 by Lizzie Moratti and Dani Cronce of Leviathan Security Group, TunnelVision abuses DHCP option 121, a standard feature that lets a network’s DHCP server push “classless static routes” to clients. An attacker who runs a rogue DHCP server on your network pushes routes that are more specific than the catch-all route most VPNs use. Because more specific routes win, the chosen traffic leaves through the physical interface instead of the tunnel (Leviathan, 2024).

During the attack the VPN’s control connection stays up, so the app keeps reporting that you are protected and a kill switch does not fire. The researchers say the technique may have been possible since 2002. Android does not implement DHCP option 121, so it is not affected; Windows, Linux, macOS and iOS are.

NVD describes the impact as an attacker on the same local network being able to read, disrupt or possibly modify traffic that was expected to be protected (NVD, 2024). NVD’s reference list includes advisories or bug notes from enterprise VPN vendors such as Cisco, Fortinet, Palo Alto Networks, Citrix, F5 and WatchGuard.

The researchers’ suggested mitigations are network namespaces on Linux (their preferred fix), firewall rules that block traffic not going through the VPN interface, ignoring option 121 (which can break some networks), or connecting through a personal hotspot or a virtual machine that is not exposed to a hostile DHCP server.

TunnelCrack: LocalNet and ServerIP (2023)

TunnelCrack, presented at USENIX Security 2023 by researchers from KU Leuven, NYU and NYU Abu Dhabi, describes two attacks that work regardless of the VPN protocol in use (TunnelCrack, 2023).

In the LocalNet attack, the attacker runs a malicious Wi-Fi network, for example by cloning a familiar hotspot name, and tells the victim that its local subnet is a public IP range that contains the target website. Because most VPN apps allow direct access to the local network, traffic to that website bypasses the tunnel.

ServerIP exploits the fact that many VPNs do not tunnel traffic to the VPN server’s own IP address. An attacker who spoofs the DNS reply for the VPN server’s hostname can point it at a target site’s IP address, relay the VPN connection so it still works, and then receive the victim’s plaintext traffic to that site. This one can also be carried out by a malicious internet provider.

The team tested more than 66 VPNs on five platforms:

PlatformLocalNet resultSource
iOSAll VPN apps vulnerableTunnelCrack, 2023
macOSAll but one client vulnerableTunnelCrack, 2023
WindowsLarge majority vulnerableTunnelCrack, 2023
LinuxMore than one-third vulnerableTunnelCrack, 2023
AndroidAbout one-quarter vulnerableTunnelCrack, 2023

For ServerIP, the built-in VPN clients of Windows, macOS and iOS were vulnerable, while Android 12 and later were not. The researchers’ recommended fix for vendors is to send all traffic through the tunnel except traffic generated by the VPN app itself.

The NVD entries for the TunnelCrack CVEs name specific products, such as Clario VPN for macOS or the WireGuard client 0.5.3 on Windows, but note that the researchers use the same IDs for the attack classes in general (NVD, 2023).

How the two disclosures relate

Mullvad, one VPN provider that published an assessment, called TunnelVision very similar to the LocalNet attack. In May 2024 it reported that firewall rules in its Windows, macOS and Linux apps blocked both attacks, Android was unaffected, and its iOS app remained vulnerable pending a fix (Mullvad, 2024). That pattern, desktop protected by a firewall and iOS harder to fix, matches the TunnelCrack platform results.

Attacks on connection tracking

Blind in/on-path attacks (CVE-2019-14899)

CVE-2019-14899, published by NVD in December 2019, describes how an attacker controlling a Wi-Fi access point, or sitting next to a victim on the same network, can determine whether the victim is using a VPN, infer which sites they are visiting, and inject data into active TCP connections inside the tunnel. NVD lists Linux, FreeBSD, OpenBSD, macOS, iOS and Android as affected (NVD, 2019). A USENIX Security 2021 paper by William Tolley, Jedidiah Crandall and colleagues analyzed this class of “blind in/on-path” attacks across many VPNs; its client-side findings received two CVEs and partial vendor fixes, while the server-side variants had not been addressed and were still feasible against all operating systems and VPN servers tested (Tolley et al., 2021).

The client-side attack can be blocked by strict source address validation, but a 2025 follow-up notes that mobile phones default to a loose setting (Mixon-Baca et al., 2025).

Port shadow (CVE-2021-3773)

Presented at the Privacy Enhancing Technologies Symposium in July 2024, the port shadow attack targets VPN servers rather than clients. An attacker who connects to the same VPN server as the victim can abuse the server’s shared connection-tracking table to place themselves between the victim and the server. From there, according to the Citizen Lab summary, they can deanonymize the connection, redirect DNS requests, port-scan the victim or hijack connections, but not decrypt the tunnel (Citizen Lab, 2024).

The researchers found Linux servers most vulnerable, with FreeBSD also affected, across OpenVPN, WireGuard and OpenConnect. They report that fixes to Linux’s Netfilter were attempted and then reverted over compatibility concerns. Their recommendations for providers include randomizing source ports, blocking clients from using the server’s listening port and limiting simultaneous connections per user.

How to test and protect yourself

You can reduce exposure without specialist tools:

  • Keep VPN apps and operating systems updated. Many vendors patched TunnelCrack and TunnelVision after disclosure; the TunnelCrack site maintains disclosure details and a list of patched VPNs.
  • Turn off “allow LAN access” unless you need it. LocalNet exploits exactly that convenience.
  • Use your own hotspot on untrusted Wi-Fi. Both TunnelVision and LocalNet need control of the local network; a phone hotspot you control removes that attacker.
  • Prefer clients that firewall non-tunnel traffic. These attacks exploit routing-only designs, and firewall rules stopped them in Mullvad’s desktop apps.
  • On Linux, consider network namespaces for sensitive work, the fix Leviathan rated most robust.
  • Check vendor advisories by CVE. Search your provider’s or employer’s VPN documentation for CVE-2024-3661 and the TunnelCrack IDs.

Researchers have published proof-of-concept code and test instructions for TunnelVision and TunnelCrack. Use them only on networks and devices you own.

What this means for you

For most people, these are local-network attacks: the danger is greatest on public or shared Wi-Fi, which is also where people most rely on a VPN. A VPN still encrypts what goes through the tunnel; the risk is traffic that never enters it. iPhone and Mac users have historically been most exposed to routing-table attacks, Android users least. Port shadow is different: it depends on your provider’s server configuration, so it is a reason to favor providers that publish security audits and respond to research.

Methodology and limitations

The sources are primary: researcher disclosures (Leviathan Security Group, the TunnelCrack site, Citizen Lab), peer-reviewed papers (PETS 2015, USENIX Security 2021, FOCI 2025), CVE records and CVSS scores retrieved from the NIST NVD API, and one vendor impact assessment (Mullvad). VPN review sites’ summaries and rankings were not used.

Vulnerability results reflect the products and versions tested at the time of each study. Many apps have since been patched, so the percentages should not be read as current failure rates. CVSS scores describe theoretical severity, not how often an attack occurs; the sources we reviewed did not document these specific techniques being used against consumers in the wild. Vendor statements about their own exposure, such as Mullvad’s, were not independently verified.

Sources

  1. CVE-2024-3661: TunnelVision - How Attackers Can Decloak Routing-Based VPNs For a Total VPN Leak — Leviathan Security Group, 2024-05-06
  2. CVE-2024-3661 Detail — NIST National Vulnerability Database, 2024-05-06
  3. TunnelCrack: Widespread design flaws in VPN clients — KU Leuven, NYU and NYU Abu Dhabi, 2023-08-08
  4. CVE-2023-36672, CVE-2023-35838, CVE-2023-36673, CVE-2023-36671 Detail — NIST National Vulnerability Database, 2023-08-09
  5. Vulnerabilities in VPNs: Paper presented at the Privacy Enhancing Technologies Symposium 2024 — The Citizen Lab, 2024-07-16
  6. CVE-2021-3773 Detail — NIST National Vulnerability Database, 2022-02-16
  7. Blind In/On-Path Attacks and Applications to VPNs — Tolley et al., USENIX Security 2021, 2021
  8. CVE-2019-14899 Detail — NIST National Vulnerability Database, 2019-12-11
  9. A Glance through the VPN Looking Glass: IPv6 Leakage and DNS Hijacking in Commercial VPN clients — Perta et al., Proceedings on Privacy Enhancing Technologies, 2015
  10. Hidden Links: Analyzing Secret Families of VPN Apps (FOCI 2025) — Mixon-Baca, Knockel, Crandall (ASU / Citizen Lab), 2025-07
  11. Evaluating the impact of TunnelVision — Mullvad VPN, 2024-05-07
Cite this research: PhantomGuide Research Team, “TunnelVision, TunnelCrack and Other Attacks on the VPN Tunnel, Explained”, PhantomGuide, 2026-10-01, https://phantomguide.com/research/vpn-protocol-attacks/

More Research