iOS Vulnerability Prevents VPNs From Encrypting All Traffic

A vulnerability affecting iOS 13.3.1 and later prevents virtual private networks (VPNs) from encrypting all traffic, allowing some internet connections to bypass encryption, potentially exposing users' data and IP addresses.

ios device network ip wireshark

A screenshot from ProtonVPN demonstrating exposed connections to Apple's servers that should be protected by the VPN

Details on the vulnerability were shared today by Bleeping Computer after it was discovered by ProtonVPN. The vulnerability is caused because iOS isn't terminating all existing connections when a user connects to a VPN, allowing them to reconnect to destination servers once the VPN tunnel has been established.

Connections made after connecting to a VPN on an iOS are not affected by this bug, but all previously established connections are not secure. This could potentially lead to a user who believes they are protected accidentally exposing IP an address and therefore, an approximate location.

Apple's Push Notifications are cited as an example of a process using connections on Apple's servers that aren't closed automatically when connecting to a VPN, but it can affect any app or service running on a user's device.

VPNs cannot work around the issue because iOS does not allow VPN apps to kill existing network connections, so this is a fix that will need to be implemented by Apple. Apple is aware of the vulnerability and is looking into options to mitigate it.

Until fixed, VPN users can connect to a VPN server, turn on Airplane Mode and then turn off Airplane Mode to kill all existing connections. The mitigation isn't entirely reliable, however, so iPhone and iPad owners who rely on VPNs should be careful until Apple puts out a fix.

Top Rated Comments

Will Tisdale ? Avatar
51 months ago

This is 100% fake and not a bug. All VPNs, such as those on the desktop, do this by default unless specifically configured, as to not interrupt ongoing downloads, or worse, cause UDP-based services to silently fail.
I don’t think so.
iOS used to handle this correctly, then stopped.
Not tearing down existing connections completely undermines the point of a VPN.
Score: 11 Votes (Like | Disagree)
Will Tisdale ? Avatar
51 months ago

Nope. I have two full tunnels on two different clients (Cisco Anyconnect, and Pulse Secure)
Well, I can tell you that Anyconnect will tear down any active connections, assuming it’s configured correctly. My work VPN certainly does.

TCP is designed to retry after being torn down. It’s no biggie.

The fact is, this is an iOS bug, which was introduced recently.
Score: 5 Votes (Like | Disagree)
konqerror Avatar
51 months ago
This is 100% fake and not a bug. All VPNs, such as those on the desktop, do this by default unless specifically configured, as to not interrupt ongoing downloads, or worse, cause UDP-based services to silently fail. Windows built-in VPN client has this exact same behavior.
Score: 3 Votes (Like | Disagree)
Westside guy Avatar
51 months ago
I’m sometimes stunned by the upvotes people get for posting incorrect information.

If a VPN is configured to send all network traffic through the VPN when it’s running - which is typically what‘s done - then all traffic should be routing through it from the moment it’s enabled. Not just connections to new end points established afterward - all traffic.

Even if a VPN is configured to just carry traffic to a few specific end points (such as the OpenVPN tunnel to our servers, which I’m relying on heavily right now due to the stay at home order currently in place here in Washington): if you’re already connected to one of those end points before establishing the tunnel, you would expect all further traffic to go through the tunnel. The idea that you wouldn’t is ludicrous.
Score: 3 Votes (Like | Disagree)
Will Tisdale ? Avatar
51 months ago

I feel like we need more info here.

As others have said, it would be problematic to silently kill existing connections when connecting to a VPN. That's certainly not the behavior I would expect. I suppose it depends on whether you use a VPN to add certain networks (such as your corporate office), or to globally route all your traffic (such as for privacy reasons). In the former case, I don't want my non-office connections to be reset.

If MacRumors is reporting this right and VPN apps cannot reset connections, that makes me wonder what changed here. Did iOS previously indeed terminate any open socket when connecting?
I feel that people need to learn about the expected behaviour of VPNs before commenting.
There’s actually two types on iOS. Split vpn and full tunnel. Split allows some stuff to be routed elsewhere. Full tunnel tunnels everything.
Score: 3 Votes (Like | Disagree)
Square-Eyes Avatar
51 months ago
I got caught out by the fact that if you tether a device to your phone it will bypass the phone’s VPN ??‍♂️
Score: 2 Votes (Like | Disagree)

Popular Stories

Beyond iPhone 13 Better Blue Face ID Single Camera Hole

Six Reasons to Wait for Next Year's iPhone 17

Thursday February 22, 2024 4:20 am PST by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models concurrently, which is why we sometimes get rumored feature leaks so far ahead of launch. The iPhone 17 series is no different, and already we have some idea of what to expect from Apple's 2025 smartphone lineup. If you plan to skip...
iPhone Notch

Apple Explored These Notch and Dynamic Island Designs for iPhones

Friday February 23, 2024 2:05 pm PST by
With the iPhone 14 Pro models in 2022, Apple introduced the Dynamic Island, which can morph and expand to display system alerts, sports scores, and a variety of other information. The feature makes the space surrounding the front camera and Face ID sensors useful compared to the notch on older iPhone models. Apple explored a variety of ideas for the iPhone's notch area over the years before...
General Apps Messages

iOS 17.4 to Add This 'Groundbreaking' New Messaging Feature

Friday February 23, 2024 5:05 am PST by
With iOS 17.4, set to arrive in March 2024, Apple is bringing a new cryptographic security feature to iMessage called PQ3. This "groundbreaking" and "state-of-the-art" protocol provides "extensive defenses against even highly sophisticated quantum attacks," according to Apple. Let's break down what that means. Apple's iMessage service already supports end-to-end encryption, but security...
cracked glass vision pro

Handful of Apple Vision Pro Units Develop Identical Crack in Cover Glass

Friday February 23, 2024 4:46 am PST by
A small number of Apple Vision Pro owners have claimed that their headsets developed a hairline crack down the middle of the front cover glass, despite having never been dropped or mishandled. Photo of hairline crack in Vision Pro front glass (credit: Reddit user Inphenite) The first report was posted in the subreddit /r/VisionPro about 18 days ago, and several more have appeared in the last...
New Macs iPads iOS 17 4

What to Expect at Potential Apple Event in March: iPads, Macs, and More

Friday February 23, 2024 8:35 am PST by
Apple often holds its first media event of the year in March, so the company could be just weeks away from announcing new products. Below, we have outlined what to expect from a potential Apple Event this March. Past Apple Events in March Apple has held five events in March since 2015:Monday, March 9, 2015 Monday, March 21, 2016 Tuesday, March 27, 2018 Monday, March 25, 2019 Tuesday,...
iOS 17

When Will Apple Release iOS 17.4 for iPhones?

Friday February 23, 2024 11:56 am PST by
Apple has been beta testing iOS 17.4 for nearly a month now. Below, we explain when the update is likely to be released to all users. In its press release announcing major App Store changes in the EU, which were implemented in response to new regulations under the EU's Digital Markets Act, Apple confirmed that iOS 17.4 will be released at some point in March:Developers can learn about these...
Next Generation CarPlay Porsche 1

Apple Launching Next-Generation CarPlay This Year With These New Features

Wednesday February 21, 2024 2:03 pm PST by
Apple recently updated its website to confirm that the first vehicle models with next-generation CarPlay support will debut "in 2024." This wording is shown on Apple's regional websites for the U.S., Canada, Australia, New Zealand, and many other countries. The iOS 17.4 beta includes code-level references to eight new CarPlay apps:Auto Settings: This app will let you manage paired iPhones...