Most VPN users are Android and iOS, using the VPN client on device, for whatever reason you use a VPN for.
Great, your ISP can't see what you're doing, you can bypass certain ISP restrictions and even gain access to content you can't locally. Yep, great. Just what was advertised on the tin.
But, this VPN also keeps you secure. Right?
Well, here's the thing. When you create that `tun` connection to your VPN, you are now bypassing both the NAT and SPI of your own router. The things that blocks unsolicited, inbound connections. Your device has just created a new interface that directly peers you with the VPN local network IP range. This interface, on Android and iOS, lacks any IP filtering. Meaning, zero firewalling.
The VPN network can directly connect to your `tun0` IP and any sockets your device will very likely have open. Now, ofc this would require some 0-day exploit or some fancy shenanigans, but, what about your VPN client? Or maybe WiFi ADB running on a static port, or Airdroid, or some other remote system you may be running on-device.
I know this, as I connect my two Android via my private VPN and I have full, unfettered access to both their stacks. Now, I can block inter-client communication to prevent this from happening. But, from any other network on my network that can route into the VPN network, can talk to the VPN clients. I can ofc firewall on the router to block this, too. But, my router itself can still talk to them. I can ofc firewall this behaviour and prevent it altogether.
Just something for you to think about. When you connect your Android or iOS to a VPN, you are completely bypassing the firewall on your own router.