From 1e06a018d08fd099289b2d6c5c1df1fd5f38493e Mon Sep 17 00:00:00 2001
From: Daniel Micay
Android allows DNS queries from the system resolver to leak to the network - provided DNS servers when a VPN app goes down due to a race condition. This is - fully prevented by GrapheneOS through extending the leak blocking to this part - of the system resolver.
+ provided DNS servers when a VPN app goes down due to a race condition. It also + similarly allows connections to the VPN DNS servers to happen outside of the VPN + tunnel. Both of these are fully prevented by GrapheneOS through extending the + leak blocking to this part of the system resolver, fully preventing unicast DNS + leaks.Android allows processes including apps to bypass the VPN entirely whether it's up or down by sending multicast packets either directly or by causing the