

This 0day reduces the complications of using other techniques that the victim would discover they’re being tracked. Even if you use a Graphene and you have any of the apps like Signal that use Electron, you will be tracked. I remember Dessalines addressed this before that Signal leaks IP but they didn’t know it because Electron. All you need to do is just ping a packet to make contact with the victim’s device app and that device will ping back your location. It was Iran who also published that WhatsApp and Messenger use ping scan to map network, and mentioned IP leaking.
It doesn’t matter if you put the app in lockdown mode because as long as it allows to receive traffic from outside world the attacker can make contact with your device. I think people don’t understand the risk that they don’t need to compromise your device like fancy Pegasus, all they need to do is just send empty packet to the app that uses Electron and it will ping back literally immediately your location. You can even say that it’s an NSA backdoor because every time there’s a thread brings up about the IP leak the devs immediately shut down the discussion and claim it’s not their fault, despite every single social media app out there including Signal uses Electron. Matrix is the only app immune to this because it doesn’t use Electron for web app.