New vulnerability lets attackers sniff or hijack VPN connections
Summary
Academics have disclosed this week a security flaw impacting Linux, Android, macOS, and other Unix-based operating systems that allows an attacker to sniff, hijack, and tamper with VPN-tunneled connections. "This allows us to inject data into the TCP stream and hijack connections," said William J. Tolley, one of the three members of the Breakpointing Bad research team at the University of New Mexico. Donenfeld described CVE-2019-12899 as a "nice vuln[erability]" while Colm MacCárthaigh, an Amazon Web Services engineer and member of the Apache HTTPd development team, described the attack as "very impressive. " According to the research team, the attack relies on sending unsolicited network packets to a victims device (Linux router, Android phone, macOS desktop, etc. The cleverness of the attack resides in how the research team crafted these packets, and the way in which they used the replies to infer what the user was doing inside their VPN tunnel.