Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AtlasVPN Linux client version 1.0.3 had a vulnerability that could let a malicious website disconnect the VPN and expose a user’s real IP address. AtlasVPN later said the flaw was fixed in Linux app version 1.1, as of September 18, 2023. That is a historical patch statement, not confirmation that version 1.1 or AtlasVPN’s Linux client is supported today.

What the AtlasVPN vulnerability did

The issue affected AtlasVPN’s Linux client version 1.0.3. A user could be exposed after visiting a website hosting malicious JavaScript: the site could cause the VPN client to disconnect, potentially revealing the user’s real IP address to the site.

SecurityWeek reported that the researcher’s technical explanation involved two components: a background daemon, atlasvpnd, that managed connections, and the user-facing atlasvpn client. The client exposed a local API on port 8076 without authentication. According to the researcher’s account, a browser could reach that API and submit a request to disconnect the VPN. SecurityWeek’s report did not attribute this technical account to a named researcher.

What an attacker could—and could not—do

The reported consequence was interruption of the VPN connection and possible disclosure of the user’s real IP address. AtlasVPN described the application and encrypted traffic between the user and VPN gateway as being disconnected by a malicious actor. The report does not say that the flaw decrypted traffic or gave an attacker access to the contents of an encrypted VPN session.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The attack description depended on a user visiting a site hosting the exploit code. It was not presented as a remote attack that could disconnect any AtlasVPN user without that interaction.

Which version was affected, and which version did AtlasVPN say fixed it?

Linux app version Status in the 2023 report
1.0.3 Identified as affected by the vulnerability.
1.1 AtlasVPN said the vulnerability was no longer present in the latest Linux app as of September 18, 2023, and that users had been informed to update.

These version details reflect the disclosure and the vendor’s statement reported by SecurityWeek in 2023. The report does not establish whether version 1.1 remains available, whether it is still supported, or which AtlasVPN Linux version is current now. Do not treat the historical version number as a present-day download recommendation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

AtlasVPN’s response to the disclosure

After the disclosure, AtlasVPN apologized for its slow response to the researcher’s attempts to find a reporting channel and said it was working on a patch. In an update dated September 18, 2023, SecurityWeek reported the company’s statement that the flaw was fixed in the latest Linux app and users had been told to update. AtlasVPN also said it was refining internal communication and establishing a more structured vulnerability reporting mechanism. These are the company’s statements as reported at that time, not an independent assessment of current support or security.

What affected Linux users should take from the report

  • If you used AtlasVPN Linux client 1.0.3, the report identified that version as affected.
  • AtlasVPN’s historical remediation was to update to version 1.1, which it said was fixed on September 18, 2023.
  • Because the report does not establish current client availability or support, verify the currently supported version through AtlasVPN’s official channels before relying on an old installer or version number.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.