Skip to content
Book Open access

Unintended Revelations and Risks: Understanding Cellular DNS Leakage on the Public Internet

Oct 2026 · Proceedings of the 2026 ACM Internet Measurement Conference · 0 citations · 68 references

Abstract

Modern cellular networks rely on DNS-based service discovery to select internal control-plane and data-plane functions. Such queries are intended to remain within operators' private namespaces, yet misconfigurations can leak them to the public Internet. Despite warnings from 3GPP and IETF decades ago, the prevalence and security implications of such leakage remain unexamined. We present the first large-scale measurement of cellular service-discovery DNS leakage. By analyzing two days of B-root traffic for each year from 2021 to 2025 and identifying internal cellular queries via 3GPP naming patterns, we observed 13.46 million leaked queries from 139 countries, covering 135,845 unique FQDNs. Most leakage (93.10%) was sporadic, suggesting operators remediated issues over time, yet a small set showed persistent leakage across all five years. Leakage frequently arose in cross-operator and cross-country scenarios, consistent with roaming behavior. While the increased load on B-root is minimal (0.02% on average), leaked names often encode internal deployment parameters (e.g., base-station identifiers), exposing information that operators do not otherwise publish. Using open-source testbeds, we further show that an on-path adversary can redirect service-discovery responses once such queries leave the operator's network, which would otherwise be infeasible without the leak. Our work highlights the need for stricter DNS isolation in cellular networks.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.