Researchers have discovered a novel technique, dubbed TunnelVision, that allows attackers to bypass VPN encapsulation and force a target user's traffic off their VPN tunnel using built-in features of DHCP. This technique, also known as decloaking, can be used to snoop on a user's traffic without their knowledge. The vulnerability is possible due to the way VPNs configure routing tables and can be mitigated by using network namespaces on Linux-based operating systems. A fix exists, but it may introduce a side channel that could be used for targeted denial-of-service censorship.