Tor VPN Beta brings isolated app-by-app Tor routing to Android

The Tor Project's new Android beta creates separate Tor circuits for each app, offering stronger anonymity than traditional VPNs.

By Central
Highlights
  • Tor VPN creates a separate Tor circuit for each Android app, making it harder to correlate user activity across apps.
  • The beta addresses a long-standing gap in mobile privacy by extending Tor protections beyond the browser.
  • Early testing showed strong demand from users in heavily censored countries seeking to bypass internet restrictions.

The Tor Project has released a new beta of Tor VPN for Android, introducing a privacy architecture that routes traffic from individual mobile applications through the Tor network rather than confining Tor protection to the browser. Unlike conventional VPNs that tunnel all device traffic through a single encrypted connection, Tor VPN creates a separate Tor circuit for each application, making it substantially harder for network observers to correlate activity across different apps to the same user. This development addresses a long-standing gap in mobile privacy: until now, users who wanted Tor-grade anonymity on their phones had few options beyond using Tor Browser, leaving messaging apps, email clients, social media feeds, and other mobile software connected through their regular, trackable IP addresses.

The project says early testing has shown particularly strong demand from users seeking to bypass internet censorship in restrictive regions, where the ability to route any app through Tor can mean the difference between accessing critical information and being cut off entirely. Tor VPN remains beta software and is not designed to match commercial VPNs on raw connection speed, but its architectural choices reflect a deliberate prioritization of anonymity and censorship circumvention over performance metrics that typical VPN services emphasize.

Tor VPN Beta for Android: What It Is and Why It Exists

Tor VPN was first conceived in 2021 following user research showing demand for Tor protections across messaging, social media, email, and other mobile applications. A limited Android release began last fall, and the Tor Project used feedback and usability testing to refine the software before announcing its latest beta on September 9. The Tor Project is a nonprofit organization that develops Tor Browser and maintains the Tor anonymity network, which routes connections through multiple relays to conceal users’ source IP addresses and make traffic analysis more difficult. Tor VPN extends those protections beyond individual browser sessions to Android applications, effectively allowing any app on the device to communicate over the Tor network.

According to the Tor Project, adoption during that testing period was especially strong in heavily censored countries. This pushed the development team to prioritize circumvention features over some capabilities traditionally associated with commercial VPN services. The result is a tool that looks superficially similar to a VPN but operates on fundamentally different principles. Where a commercial VPN typically aims to provide fast, reliable access to geo-restricted content or encrypt traffic against local snooping, Tor VPN is built to maximize anonymity and defeat sophisticated censorship systems even at the cost of speed and convenience.

App-by-App Isolation: How Tor VPN Routes Traffic Differently

The defining technical feature of Tor VPN is its per-application circuit isolation. Unlike conventional VPNs, which typically send a device’s traffic through a single encrypted tunnel, Tor VPN creates a separate Tor circuit for each application. This app isolation is intended to make it harder to correlate activity from separate applications to the same user, borrowing from isolation mechanisms already used by Tor Browser to limit cross-site tracking.

In practice, this means that when a user opens their email app, that traffic travels through one Tor circuit with its own entry node, middle relays, and exit node. When they then open a messaging app, that traffic takes a completely different path through the Tor network. Even if both apps are communicating with servers that collude or are monitored by the same adversary, the adversary cannot easily determine that both streams belong to the same person because the circuits have no overlap at any point. This is a significant privacy improvement over traditional VPN setups where all traffic shares a single tunnel and, by extension, a single observable relationship between source and destination.

Users can individually select which applications are routed through Tor, with the latest interface adding search functionality to simplify managing large app lists. This selective routing allows users to keep sensitive communications anonymous while maintaining normal, faster connections for apps that do not require Tor-level privacy. A user might route their Signal messages and ProtonMail sessions through Tor while allowing YouTube or Spotify to connect directly for better performance.

What Is Tor VPN? A Complete Explanation for Privacy-Conscious Android Users

Tor VPN is a free, open-source Android application developed by the Tor Project that routes selected mobile applications through the Tor anonymity network. Unlike the Tor Browser, which only protects web traffic within the browser itself, Tor VPN extends Tor protection to any Android application the user chooses. It creates a separate encrypted path through the Tor network for each application, preventing network observers from linking activity across different apps to the same device or user. The software is currently in beta and available through Google Play, F-Droid, or direct APK download. It uses Arti, the Rust implementation of the Tor protocol, and includes censorship circumvention features such as WebTunnel bridges that disguise Tor connections as ordinary encrypted web traffic.

Censorship Resistance as a Core Design Priority

The Tor Project has focused heavily on censorship resistance throughout the beta development process. Version 1.4.0 beta added support for WebTunnel bridges, which disguise Tor connections so they resemble ordinary encrypted web traffic and are harder for network operators to identify and block. This is a critical capability in countries where the Tor network itself is blocked or where simply connecting to a known Tor relay can draw unwanted attention.

WebTunnel bridges represent an evolution in bridge technology. Earlier bridge types, such as obfs4, also attempt to obfuscate Tor traffic, but they can sometimes be identified through deep packet inspection. WebTunnel goes further by making Tor connections look like standard HTTPS traffic to a normal web server. From the perspective of a network censor, a user connecting to a WebTunnel bridge appears to be visiting an ordinary website, not accessing the Tor network. This makes WebTunnel particularly effective in environments where censors have deployed sophisticated traffic analysis capabilities.

Exit-Node Confusion: A Usability Challenge

Developers said usability testing also exposed confusion around exit-node selection. Some users trying to bypass censorship chose an exit location when they actually needed a Tor bridge. The current design therefore requires users to connect to Tor before selecting an exit, while further changes to exit selection remain under consideration. This distinction between bridges and exit nodes is a common point of confusion even for experienced privacy tool users, and the Tor Project’s iterative design work on this interface reflects the challenge of making powerful anonymity technology accessible to non-expert users.

Bridges are used to connect to the Tor network when direct connections are blocked. Exit nodes are the final relay in a Tor circuit, where traffic leaves the Tor network and connects to its destination on the open internet. Changing exit location affects what geographic region a destination server sees traffic originating from, but it does nothing to help a user connect to Tor in the first place if their ISP or government blocks known Tor relays. The Tor Project’s redesign attempts to nudge users toward the correct workflow: first establish a connection to Tor using bridges if necessary, then optionally customize exit behavior.

Under the Hood: Arti and Onionmasq

Tor VPN uses Arti, the Tor Project’s newer Rust implementation of the Tor protocol, together with the Onionmasq networking layer. Arti represents a ground-up rewrite of the Tor protocol in Rust, a systems programming language that offers memory safety guarantees without garbage collection. The Tor Project began developing Arti in 2020 to address long-standing maintenance challenges with the original C implementation, which had accumulated decades of code and was increasingly difficult to extend and audit.

Onionmasq provides the low-level networking infrastructure that Arti runs on top of, handling concerns such as packet encapsulation, network interface management, and the interaction with the Android VPN API. Together, these components form a modular architecture that the developers say has improved stability and provides reusable components that can be shared across other applications.

The Rust-based architecture is not just a matter of developer convenience. Memory safety vulnerabilities in networking software have historically been a significant source of security bugs, and Rust’s type system eliminates entire classes of these vulnerabilities at compile time. For a privacy tool that may be used by journalists, activists, and human rights defenders against well-resourced adversaries, this additional layer of security assurance is meaningful. The June 2025 security audit by Cure53 examined this architecture and confirmed that no fundamental flaws existed in Tor tunnel establishment or traffic routing.

The software also offers reproducible builds and distribution through F-Droid, allowing users to verify that distributed binaries match published source code and install the application without relying on Google Play. APK downloads remain available as well. Reproducible builds are particularly important for privacy tools because they allow technically sophisticated users to independently confirm that the binary they are installing has not been tampered with or backdoored between compilation and distribution. For users in high-risk environments, this verification capability can be the difference between a functioning privacy tool and a compromised one.

Security Audit: Cure53 Findings and Remediation

Tor VPN’s underlying architecture previously underwent a June 2025 security review by Cure53. The audit found no fundamental flaws in Tor tunnel establishment or traffic routing, but it identified several issues involving DNS handling, input validation, denial-of-service risks, and other hardening opportunities that the project said it was addressing. This external audit is part of the Tor Project’s ongoing security assurance practice and provides independent validation of the software’s security posture.

The DNS handling issues are worth examining because they highlight the subtleties of building privacy tools on mobile operating systems. When an Android application makes a network request, the operating system typically resolves domain names through system DNS servers, which may be operated by the mobile carrier or another entity the user does not trust. If the VPN does not intercept and reroute these DNS queries, the user’s privacy is compromised before any Tor circuit is even established. The audit examined whether Tor VPN properly handles DNS at each stage of the connection process and identified edge cases where DNS leaks could occur. The project has been working on patches to close these gaps.

Input validation issues can be exploited by malicious applications on the device to crash the VPN service or cause it to misroute traffic. Denial-of-service risks could allow an attacker to prevent the VPN from functioning, potentially forcing traffic to fall back to an unencrypted connection. While none of these findings were categorized as critical vulnerabilities, they represent the kind of hardening work that distinguishes production-ready software from a promising prototype. The Tor Project’s willingness to conduct and publish external audits even during the beta phase of development signals a commitment to getting the security fundamentals right before marking the software as stable.

What Tor VPN Is Not: Honest Comparisons with Commercial VPNs

The Tor Project has been candid about the limitations of Tor VPN relative to commercial VPN services. Tor VPN remains beta software and is not designed to match commercial VPNs on raw connection speed. Tor routing inherently adds latency because traffic passes through three relays in different geographic locations, and the Tor network’s capacity is limited by volunteer-operated relays rather than commercial infrastructure. Users who need high-bandwidth connections for streaming, gaming, or large file transfers will likely find Tor VPN unsuitable for those applications. The selective routing feature becomes essential here: users can route only their sensitive communications through Tor while keeping bandwidth-intensive activities on a direct connection or a commercial VPN.

Commercial VPNs also typically offer features that Tor VPN does not, such as kill switches, split tunneling with more granular controls, dedicated IP addresses, port forwarding, and customer support. Tor VPN’s priorities are different. It is optimized for anonymity rather than convenience, for censorship resistance rather than geo-unblocking, and for verifiable security rather than polished user experience. Users who need to bypass Netflix region locks or hide torrenting activity from their ISP are not the target audience. Users who need to communicate securely while living under a regime that monitors and censors internet activity are exactly the target audience.

The Tor Project says upcoming work will focus on stronger circumvention, usability improvements, and adding performance features, including congestion-control capabilities from Tor’s older C implementation to Arti. Congestion control is a mechanism for managing network traffic to prevent packet loss and maintain fair bandwidth distribution among users. The C implementation of Tor has sophisticated congestion control that has been developed and refined over many years; bringing these capabilities to Arti will improve the performance of Tor VPN and other Arti-based applications.

How Tor VPN Compares to Tor Browser on Android

Many Android users already have access to Tor Browser, which routes all browser traffic through the Tor network. Tor VPN extends this protection to the entire device, but the relationship between the two tools is complementary rather than competitive. Tor Browser includes additional privacy features that Tor VPN does not directly provide, such as anti-fingerprinting measures that standardize browser behavior across users to make tracking through browser characteristics more difficult. Tor Browser also automatically isolates each website into its own Tor circuit, which Tor VPN does at the application level rather than the website level.

For a user who only needs anonymous web browsing, Tor Browser remains the simpler and more thoroughly hardened choice. For a user who needs to use multiple applications anonymously, or who wants to ensure that all network traffic from their device is protected even when they are not actively browsing, Tor VPN fills a clear gap. The two tools can be used together: a user could run Tor Browser with its full privacy protections while also using Tor VPN to route Signal messages or email traffic through Tor.

Practical Considerations for Android Users

Android users can obtain Tor VPN Beta through Google Play, F-Droid, or directly as an APK. Users in censored environments should configure bridges when direct Tor connections are blocked rather than relying solely on exit-location changes. This is the most important practical advice for new users: if you are in a country where Tor is blocked, you need a bridge to connect. Changing your exit location to a country with more permissive internet policies will not help you connect to Tor in the first place; it only affects where your traffic appears to originate once you are already connected.

The app’s interface allows users to see which applications are currently being routed through Tor and to toggle routing on or off for each app individually. The search functionality added in the latest beta is significant because even a modest Android installation can have hundreds of applications, making manual scrolling impractical. Users can also configure whether to use bridges automatically, which bridges to use, and whether to request a bridge from the Tor Project’s bridge distribution system.

The connection indicator in the app shows whether Tor is properly connected, how many hops the current circuit is using, and whether bridges are in use. Debug logging is available for troubleshooting, which can be helpful when diagnosing connection problems in restrictive environments. The Tor Project recommends testing the app in a non-censored environment first to familiarize yourself with the interface before relying on it in a high-risk context.

The Future of Tor VPN and Mobile Anonymity

The Tor VPN beta represents a significant step toward making Tor-grade anonymity available across the entire mobile experience rather than confining it to a single browser. The architectural decisions the Tor Project has made, from Rust-based implementation to per-application circuit isolation to reproducible builds, reflect a consistent prioritization of security and verifiability over convenience and performance. This is the right set of trade-offs for the tool’s intended audience, which includes some of the most at-risk internet users in the world.

The development trajectory of Tor VPN will be shaped by the same forces that have guided the Tor Project for the past two decades: the evolving tactics of internet censors, the changing landscape of mobile operating systems, the feedback of users who depend on Tor for their safety, and the project’s commitment to keeping the technology free and open source. As WebTunnel bridges improve and as congestion control from the C implementation is ported to Arti, Tor VPN will become both more usable and more resilient against increasingly sophisticated blocking attempts. For now, the beta is a functional and meaningful privacy tool in its own right, one that extends the reach of the Tor network into areas of mobile usage where it has never before been available. The Android users who need it most, those living under censorship regimes for whom every app connection carries risk, now have a new and powerful option for protecting their communications from surveillance and control.

Share This Article