Security researchers have identified serious vulnerabilities in the Mullvad VPN service , which could allow hackers to execute malicious code and compromise users' privacy.

The vulnerabilities were discovered during a detailed security audit by the company X41 D-Sec GmbH in late 2024.
See also: The best VPN apps for 2024
Among the most critical issues were race conditions and memory safety violations in Mullvad's signal handling code. These vulnerabilities could lead to memory corruption and malicious code execution. While exploiting these issues is technically difficult, there is a chance of success if an attacker can time the signals correctly.
Additionally, a serious vulnerability was identified that allows “DLL bypass” when installing Mullvad VPN on Windows, allowing malicious code to be executed. Other vulnerabilities include the possibility of revealing a user’s virtual IP address or detecting whether a Mullvad client has connected to a specific website, through network-level attacks.
Read also: How to use a VPN on an Android device?
Mullvad, known for its commitment to security, has already patched most of the vulnerabilities discovered, working closely with X41. In an official statement, the company said it “takes the findings very seriously” and expressed its gratitude to X41 for their thorough review.

Despite the concerns raised, the researchers praised the overall security of the Mullvad VPN app, emphasizing that it offers a high level of protection against attacks. Users are urged to update their app to the latest version for maximum security. This incident highlights the importance of regular security checks on VPN services, especially in these days when cybersecurity is a priority.
See more: Salt Typhoon hackers target telecoms with GhostSpider backdoor
Source: cybersecuritynews
