Earlier quoted context omitted.
Can you report this to GrapheneOS?
It has been reported to Google (as a security bug) and to GrapheneOS as a comment in one of the very similar VPN leak issue on github. GrapheneOS has deleted my comment, probably because they assumed it was AI-generated or something, I've copied the report I sent to Google there.
Re: Android NAT-T keepalive offload bypasses VPN lockdown
#71[deleted]