technology

Android 16 nukes vpns for seven months and google shrugs

Seven months. That’s how long android 16 has been quietly shredding VPN tunnels, leaving millions of privacy-minded users naked on public Wi-Fi while Google insists it sees “nothing unusual.” Proton VPN spilled the beans late yesterday: every time you update a VPN client on a phone running android 16, the system’s network stack can implode, dropping the encrypted tunnel without a pop-up, a log entry, or even the courtesy of a toast message.

The bug that erases your digital invisibility cloak

Here’s the nasty trick. android 16’s new networking shim—designed to speed up hand-offs between Wi-Fi and 5G—apparently forgets to re-attach VPN sockets after an app update. The packets still flow, but they shoot out of the raw ISP interface, broadcasting your real IP, DNS requests and all. You think you’re in Iceland; your traffic is actually leaving from a Starbucks in Des Moines. Mullvad, WireGuard, TunnelBear and Proton have all confirmed the same pattern: user updates the app, the VPN icon stays green, the kill switch never triggers, yet the leak test screams “exposed.”

Google closed the first bug tracker ticket as “can’t reproduce.” Then a second. Then a third. Meanwhile, Reddit threads and one-star Play Store reviews pile up like digital driftwood. Pixel 7, 6a, 10 Pro, Galaxy S25 Ultra—flagships, budget burners, it doesn’t matter. If it’s on android 16 and you breathe near a VPN update, you’re rolling the dice.

Your only two weapons right now

Your only two weapons right now

Until Google ships a patch—something sources inside Mountain View say won’t land until at least the August quarterly drop—your choices are blunt. Reinstall the VPN app from scratch after every update, or reboot the entire phone the moment you notice the icon lingering longer than usual. Restarting just the service doesn’t cut it; the corrupted socket survives. Airplane-mode ballet? Useless. Clearing cache? Theater. A full wipe and re-install is the only reset that consistently rebuilds the network shim.

Let that sink in: a flagship ecosystem that once bragged about seamless updates now asks users to factory-reset their privacy tool once a month. And yes, the Pixel-exclusive Google VPN is also affected—android 16 Beta 3.1 torches Google’s own tunnel, which feels like the world’s most expensive dogfooding fail.

Why this leak is bigger than a glitch

Why this leak is bigger than a glitch

VPNs aren’t cat-and-mouse toys for geeks anymore. Entire newsrooms, domestic-violence shelters and gig-economy drivers rely on them to keep sources, victims and meal-delivery routes away from stalkers and state firewalls. One silent dropout can put a undocumented source on a deportation flight or expose a therapist’s home IP to a deranged client. Google’s shrug emoji response turns a technical footnote into a liability landmine.

The irony? Android 16’s marketing hook was “security hardened by default.” Instead, it weaponized the update button. Until the fix lands, treat every Play Store “Update” next to your VPN like a loaded gun: usable, but only if you’re ready to reboot your digital life right after.