Google Fuchsia and gVisor Network Stack Vulnerability Allows Predictable Protocol Header Fields

Vulnerability

A vulnerability exists in the way Google Fuchsia, using the gVisor network stack, generates certain network protocol header fields. This issue affects the TCP initial sequence number, TCP timestamp, TCP and UDP source ports, and the IPv4/IPv6 fragment ID fields. The vulnerability arises because these values can be predicted under specific conditions, enabling potential network attacks and device tracking.

Impact

The vulnerability allows for the prediction of various network protocol fields, including TCP and UDP source ports, TCP initial sequence numbers, TCP timestamps, and IPv4 fragment IDs. This predictability can be exploited for device tracking across websites and networks, as well as for other network attacks.

Reproduction

The vulnerability can be reproduced by observing the network protocol fields generated by a Fuchsia device. This can be done through a web-based tracking technique that extracts information from the TCP/IP headers of the device's traffic. The tracking can be coordinated with a server backend that computes a device ID based on the extracted header information. The same device ID can be used to track the device across different websites, networks, and browser modes.

Remediation

Google has issued patches for the vulnerabilities in Fuchsia. The specific details of these patches can be found in the Fuchsia Git repository.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
5.3
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.