Shared NAT breaks the old assumption that “same public IP” still means separation. NatJack shows an attacker on the same NAT boundary can manipulate connection tracking and take over live sessions, poison DNS replies, or knock connections offline without needing spoofed packets or local broadcast access.
Researchers disclosed the class at Black Hat and said 13 vendors were notified. They tested 32 products and configurations, and every one was vulnerable to some or all of the techniques, including affected Windows NAT and Linux kernel netfilter conntrack deployments.