PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Security expert discovered a bug that affects million Kaspersky VPN users

Posted on August 10, 2018June 25, 2025 by Dissent

Pierluigi Paganini reports:

A security issue exists in Kaspersky VPN <=v1.4.0.216 which leaks your DNS Address even after you’re connected to any virtual server. (Tested on Android 8.1.0)

What is a DNS leaks?

In this context, with the term “DNS leak” we indicate an unencrypted DNS query sent by your system OUTSIDE the established VPN tunnel.

Kaspersky VPN is one of the most trusted VPN which comes with 1,000,000+ tier downloads in the official Google Play Store, however, it was observed that when it connects to any random virtual server still leaks your actual DNS address.

The expert Dhiraj Mishra that discovered the flaw reported it to Kaspersky via Hackerone.

Read more on Security Affairs.

Related posts:

  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
Category: Misc

Post navigation

← The long and difficult road to a U.S. privacy law: Part 2
EFF Amicus Brief: The Privacy Act Requires the FBI to Delete Files of Its Internet Speech Surveillance →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations
  • U.S. Judge Blocks Trump From Cutting Medicaid Funding For Planned Parenthood In 22 States
  • India backs off mandatory ‘cyber safety’ app after surveillance backlash
  • Judge orders Trump administration to halt warrantless immigration arrests in District of Columbia

RSS Recent Posts at DataBreaches.net

  • Ex-teen hackers warn parents are clueless as children steal ‘millions’
  • UK Government Considers Computer Misuse Act Revision
  • Japan issues arrest warrant against teen suspected of cyberattack using AI
  • How old is the average hacker? What does a new research report suggest? (1)
  • Marquis data breach impacts over 74 US banks, credit unions
©2025 PogoWasRight.org. All rights reserved.