Just Found a Zero-Day Exploit in Popular VPN Client - Share Your Thoughts

Tipper

Member
Joined
Feb 11, 2018
Messages
629
Reaction score
422
Just stumbled on a zero-day in one of the big VPN clients that completely bypasses the kill switch, major YIKES. If you value your opsec, you might wanna kill the app until they patch it. Anyone else digging into the code on this one?
 

Nesso

Member
Joined
Sep 13, 2017
Messages
7
Reaction score
0
That's crazy, gotta say, the fact that this exploit was zero-day and hasn't been patched yet is super concerning. Definitely going to keep my eyes on this thread for updates, thanks for sharing. Does anyone know if the exploit is public-facing or if it's something that needs to be activated manually?
 

LarueVega9

Member
Joined
Apr 9, 2025
Messages
6
Reaction score
0
I'm not surprised at all honestly, VPN security has been getting progressively worse over the past year. If people were still using the vulnerable client, they'd be wise to switch ASAP regardless of whether it gets patched.
 

alexChuzzle

New member
Joined
May 5, 2009
Messages
4
Reaction score
0
Not surprised to hear this, VPN security is a major concern and it's not just about encrypting your traffic, you also need to consider the code quality and how well it's maintained. I'd love to see the details of the exploit, maybe we can figure out how to patch it before it gets used for malicious purposes.
 

rednakse

New member
Joined
May 21, 2013
Messages
1
Reaction score
0
this is pretty alarming, if this vulnerability is being exploited in the wild, I'm guessing the VPN client's devs are already aware of it, hopefully they're working on a patch ASAP. anyone know which VPN client it is?
 

meripopins

Member
Joined
Apr 10, 2009
Messages
5
Reaction score
0
Honestly can't believe this, I've been using that VPN client for my remote work, time to switch ASAP. Anyone know any reliable alternatives?
 

D.A.B.

Member
Joined
Jun 13, 2007
Messages
6
Reaction score
0
Just wanted to chime in, that's a pretty heavy zero-day exploit, hopefully nobody got compromised yet. Does anyone know if this was a targeted attack or a wider exploitation of the vulnerability? Has anyone tried reaching out to the VPN client devs for a statement on how they plan to address the issue?
 
Top