iOS Vulnerability Prevents VPNs From Encrypting All Traffic

A vulnerability affecting iOS 13.3.1 and later prevents virtual private networks (VPNs) from encrypting all traffic, allowing some internet connections to bypass encryption, potentially exposing users' data and IP addresses.

ios device network ip wireshark

A screenshot from ProtonVPN demonstrating exposed connections to Apple's servers that should be protected by the VPN

Details on the vulnerability were shared today by Bleeping Computer after it was discovered by ProtonVPN. The vulnerability is caused because iOS isn't terminating all existing connections when a user connects to a VPN, allowing them to reconnect to destination servers once the VPN tunnel has been established.

Connections made after connecting to a VPN on an iOS are not affected by this bug, but all previously established connections are not secure. This could potentially lead to a user who believes they are protected accidentally exposing IP an address and therefore, an approximate location.

Apple's Push Notifications are cited as an example of a process using connections on Apple's servers that aren't closed automatically when connecting to a VPN, but it can affect any app or service running on a user's device.

VPNs cannot work around the issue because iOS does not allow VPN apps to kill existing network connections, so this is a fix that will need to be implemented by Apple. Apple is aware of the vulnerability and is looking into options to mitigate it.

Until fixed, VPN users can connect to a VPN server, turn on Airplane Mode and then turn off Airplane Mode to kill all existing connections. The mitigation isn't entirely reliable, however, so iPhone and iPad owners who rely on VPNs should be careful until Apple puts out a fix.

Top Rated Comments

Will Tisdale ? Avatar
33 months ago

This is 100% fake and not a bug. All VPNs, such as those on the desktop, do this by default unless specifically configured, as to not interrupt ongoing downloads, or worse, cause UDP-based services to silently fail.
I don’t think so.
iOS used to handle this correctly, then stopped.
Not tearing down existing connections completely undermines the point of a VPN.
Score: 11 Votes (Like | Disagree)
Will Tisdale ? Avatar
33 months ago

Nope. I have two full tunnels on two different clients (Cisco Anyconnect, and Pulse Secure)
Well, I can tell you that Anyconnect will tear down any active connections, assuming it’s configured correctly. My work VPN certainly does.

TCP is designed to retry after being torn down. It’s no biggie.

The fact is, this is an iOS bug, which was introduced recently.
Score: 5 Votes (Like | Disagree)
konqerror Avatar
33 months ago
This is 100% fake and not a bug. All VPNs, such as those on the desktop, do this by default unless specifically configured, as to not interrupt ongoing downloads, or worse, cause UDP-based services to silently fail. Windows built-in VPN client has this exact same behavior.
Score: 3 Votes (Like | Disagree)
Westside guy Avatar
33 months ago
I’m sometimes stunned by the upvotes people get for posting incorrect information.

If a VPN is configured to send all network traffic through the VPN when it’s running - which is typically what‘s done - then all traffic should be routing through it from the moment it’s enabled. Not just connections to new end points established afterward - all traffic.

Even if a VPN is configured to just carry traffic to a few specific end points (such as the OpenVPN tunnel to our servers, which I’m relying on heavily right now due to the stay at home order currently in place here in Washington): if you’re already connected to one of those end points before establishing the tunnel, you would expect all further traffic to go through the tunnel. The idea that you wouldn’t is ludicrous.
Score: 3 Votes (Like | Disagree)
Will Tisdale ? Avatar
33 months ago

I feel like we need more info here.

As others have said, it would be problematic to silently kill existing connections when connecting to a VPN. That's certainly not the behavior I would expect. I suppose it depends on whether you use a VPN to add certain networks (such as your corporate office), or to globally route all your traffic (such as for privacy reasons). In the former case, I don't want my non-office connections to be reset.

If MacRumors is reporting this right and VPN apps cannot reset connections, that makes me wonder what changed here. Did iOS previously indeed terminate any open socket when connecting?
I feel that people need to learn about the expected behaviour of VPNs before commenting.
There’s actually two types on iOS. Split vpn and full tunnel. Split allows some stuff to be routed elsewhere. Full tunnel tunnels everything.
Score: 3 Votes (Like | Disagree)
Square-Eyes Avatar
33 months ago
I got caught out by the fact that if you tether a device to your phone it will bypass the phone’s VPN ??‍♂️
Score: 2 Votes (Like | Disagree)

Popular Stories

USB C Over Lightning Feature

EU Passes Law to Switch iPhone to USB-C by End of 2024

Tuesday October 4, 2022 3:30 am PDT by
The European Parliament today voted overwhelmingly in favor of enforcing USB-C as a common charging port across a wide range of consumer electronic devices, including the iPhone and AirPods, by the end of 2024. The proposal, known as a directive, forces all consumer electronics manufacturers who sell their products in Europe to ensure that a wide range of devices feature a USB-C port. This...
ipad pro purple

Five Apple Products You Should Avoid Buying Right Now

Wednesday October 5, 2022 2:12 pm PDT by
Rumors suggest that Apple still has several new devices that are coming before the end of the year, including a range of Macs and iPads. It's not looking like we're going to get an October event in 2022, but refreshes are coming soon, probably via press release. If you're planning to buy a Mac or an iPad, make sure to check out our list to know what's safe to pick up now and what's not. iPad ...
General iOS 16 Feature Yellow

10 New iOS 16 Features Coming Later This Year

Monday October 3, 2022 2:41 pm PDT by
iOS 16 was released to the public three weeks ago with a customizable Lock Screen, the ability to edit iMessages, improvements to Focus modes, and much more. And in the coming months, iPhone and iPad users have even more new features to look forward to. We've rounded up 10 new features coming to the iPhone and iPad later this year, according to Apple. Many of the features are part of iOS...
magsafe charger orange

Apple Releases New MagSafe Charger Firmware

Tuesday October 4, 2022 12:09 pm PDT by
Apple today released updated firmware for the MagSafe Charger that is designed to work with the iPhone 12 and later and the AirPods Pro 2. The new firmware is version 10M1821, up from the prior 10M229 firmware. Note that in the Settings app, you'll see a different version number than the firmware number, with the update displayed as version 255.0.0.0 (the prior firmware was 247.0.0.0). The...
maxresdefault

Video: AirPods Pro 2 vs. Bose QuietComfort II

Monday October 3, 2022 12:50 pm PDT by
Apple on September 23 officially launched the second-generation version of the AirPods Pro, introducing updated Active Noise Cancellation, Adaptive Transparency, improved sound, and more. Right around the same time, Bose introduced new QuietComfort II earbuds with many similar features, so we thought we'd compare the two to see which has the edge. Subscribe to the MacRumors YouTube channel for ...
General iOS 16 Feature Yellow

One of iOS 16's Best Features Drains Battery When Enabled

Thursday October 6, 2022 2:15 am PDT by
One of iOS 16's most praised features comes at the cost of draining battery life, according to recently published Apple support documents. The feature, known as "keyboard haptics," is optional in iOS 16 and allows users to get physical feedback via slight vibrations upon the touch of each key, confirming that it was pressed much like keyboard sounds. The feature is a useful addition to the...
aapl logo banner

No October Apple Event Expected Despite Upcoming Wave of New Devices

Wednesday October 5, 2022 2:33 am PDT by
Apple is no longer expected to host an event this month, despite plans to unveil a host of new devices including new iPad and Mac models, according to recent reports. In recent months, Apple has been expected to hold an event in October to announce a range of products that did not receive any stage time during the company's iPhone 14 unveiling event last month. In a recent newsletter, Bloombe...
iOS 16

Apple Preparing iOS 16.0.3 With More Bug Fixes Following iPhone 14 Launch

Monday October 3, 2022 7:53 am PDT by
iOS 16.0.2 was released last month with several bug fixes for iPhone 14 issues, excessive copy and paste permission prompts, and more. Now, evidence suggests that Apple is planning to release iOS 16.0.3 with additional bug fixes. Evidence of an upcoming iOS 16.0.3 software update has shown up in MacRumors analytics logs, which have been a reliable indicator in the past. There are several...
iOS 16

Apple Seeds New Betas of iOS 16.1 and iPadOS 16.1 to Developers [Update: Public Beta Available]

Tuesday October 4, 2022 10:06 am PDT by
Apple today seeded the fourth beta of iOS 16.1 to developers for testing purposes, with the beta coming one week after the release of the third iOS 16.1 beta. The iOS 16.1 beta is also joined by the fifth beta of iPadOS 16.1, which is on a slightly different schedule as Apple started testing it prior to the launch of iOS 16. Registered developers can download the iOS 16‌ and iPadOS 16...
dynamic island outline 1

iOS 16.1 Beta Adds More Pronounced Gray Border Around Dynamic Island When Using Black Wallpapers or in Dark Mode

Tuesday October 4, 2022 11:58 am PDT by
With the latest iOS 16.1 beta, Apple has tweaked the design of the Dynamic Island on the iPhone 14 Pro and Pro Max to make it more visible on a dark background. When using a darker wallpaper or with the darker interface of Dark Mode activated, there is a light gray border around the outside of the Dynamic Island when the screen is dimmed or when the Dynamic Island is in active use. The...