Unintended Revelations and Risks: Understanding Cellular DNS Leakage on the Public Internet
Abstract
Modern cellular networks rely on DNS-based service discovery to select internal control-plane and data-plane functions. Such queries are intended to remain within operators' private namespaces, yet misconfigurations can leak them to the public Internet. Despite warnings from 3GPP and IETF decades ago, the prevalence and security implications of such leakage remain unexamined. We present the first large-scale measurement of cellular service-discovery DNS leakage. By analyzing two days of B-root traffic for each year from 2021 to 2025 and identifying internal cellular queries via 3GPP naming patterns, we observed 13.46 million leaked queries from 139 countries, covering 135,845 unique FQDNs. Most leakage (93.10%) was sporadic, suggesting operators remediated issues over time, yet a small set showed persistent leakage across all five years. Leakage frequently arose in cross-operator and cross-country scenarios, consistent with roaming behavior. While the increased load on B-root is minimal (0.02% on average), leaked names often encode internal deployment parameters (e.g., base-station identifiers), exposing information that operators do not otherwise publish. Using open-source testbeds, we further show that an on-path adversary can redirect service-discovery responses once such queries leave the operator's network, which would otherwise be infeasible without the leak. Our work highlights the need for stricter DNS isolation in cellular networks.