VPNs for iOS Are Broken and Apple Knows It, Says Security Researcher

Third-party VPNs made for iPhones and iPads routinely fail to route all network traffic through a secure tunnel after they have been turned on, something Apple has known about for years, a longtime security researcher has claimed (via ArsTechnica).

settings
Writing on a continually updated blog post, Michael Horowitz says that after testing multiple types of virtual private network (VPN) software on iOS devices, most appear to work fine at first, issuing the device a new public IP address and new DNS servers, and sending data to the VPN server. However, over time the VPN tunnel leaks data.

Typically, when a users connects to a VPN, the operating system closes all existing internet connections and then re-establishes them through the VPN tunnel. That is not what Horowitz has observed in his advanced router logging. Instead, sessions and connections established before the VPN is turned on are not terminated as one would expect, and can still send data outside the VPN tunnel while it is active, leaving it potentially unencrypted and exposed to ISPs and other parties.

"Data leaves the iOS device outside of the VPN tunnel," Horowitz writes. "This is not a classic/legacy DNS leak, it is a data leak. I confirmed this using multiple types of VPN and software from multiple VPN providers. The latest version of iOS that I tested with is 15.6."

Horowitz claims that his findings are backed up by a similar report issued in March 2020 by privacy company Proton, which said an iOS VPN bypass vulnerability had been identified in iOS 13.3.1 which persisted through three subsequent updates to iOS 13.

According to Proton, Apple indicated it would add Kill Switch functionality to a future software update that would allow developers to block all existing connections if a VPN tunnel is lost.

However, the added functionality does not appear to have affected the results of Horowitz's tests, which were performed in May 2022 on an iPadOS 15.4.1 using Proton's VPN client, and the researcher says any suggestions that it would prevent the data leaks are "off base."

Horowitz has recently continued his tests with iOS 15.6 installed and OpenVPN running the WireGuard protocol, but his iPad continues to make requests outside of the encrypted tunnel to both Apple services and Amazon Web Services.

As noted by ArsTechnica, Proton suggests a workaround to the problem that involves activating the VPN and then turning Airplane mode on and off to force all network traffic to be re-established through the VPN tunnel.

However, Proton admits that this is not guaranteed to work, while Horowitz claims Airplane mode is not reliable in itself, and should not be relied on as a solution to the problem. We've reached out to Apple for comment on the research and will update this post if we hear back.

Top Rated Comments

xxray Avatar
11 weeks ago
I remember this getting reported on a couple years ago, and never getting an update. I just assumed it had been fixed.

I’m so glad my privacy has been compromised for the last 2.5 years and still is being compromised while Apple knows about it and does nothing about it.
Score: 64 Votes (Like | Disagree)
antiprotest Avatar
11 weeks ago
While other companies screw you on the cloud, Apple screws you "on device."
Score: 44 Votes (Like | Disagree)
BootsWalking Avatar
11 weeks ago
This may seem like a benign annoyance but some people rely on VPNs for very important situations, like reporters who need it to protect their sources or themselves.
Score: 44 Votes (Like | Disagree)
arkitect Avatar
11 weeks ago
Ah, well that probably explains why on my last trip to *cough* a country that shall remain unnamed, but where the Fruit company has many things manufactured *cough* my VPN went tits up and I was unable to use my favourite search engine.

FFS Apple!
Score: 31 Votes (Like | Disagree)
VulchR Avatar
11 weeks ago
Nice to know Apple was faffing about with CSAM stuff while this vulnerability just sat there. Perhaps Apple should refund those of us who pay for VPN services? I live in the UK, where pretty much everybody, at every level of government, can gain access to your browsing history unless you use a VPN.
Score: 29 Votes (Like | Disagree)
JM Avatar
11 weeks ago
Come on, y’all. Little ol’ Apple is doing the best they can. Bless their heart.
Score: 24 Votes (Like | Disagree)

Related Stories

Lockdown Mode Feature

iOS 16 VPN Tunnels Leak Data, Even When Lockdown Mode Is Enabled

Thursday October 13, 2022 8:41 am PDT by
iOS 16 continues to leak data outside an active VPN tunnel, even when Lockdown mode is enabled, security researchers have discovered. Speaking to MacRumors, security researchers Tommy Mysk and Talal Haj Bakry explained that iOS 16's approach to VPN traffic is the same whether Lockdown mode is enabled or not. The news is significant since iOS has a persistent, unresolved issue with leaking...
apple security research

Apple Launches New Security Research Website

Thursday October 27, 2022 12:05 pm PDT by
Apple today introduced Apple Security Research, a new website that is dedicated to improving the methods available to security researchers for reporting issues to Apple. The site offers up tools for sending Apple security reports, getting real-time status updates, and communicating with Apple engineers. In addition to housing information on the Apple Security Bounty program, the website is a ...
iOS 15 General Feature Purple

Apple Releases iPadOS and iOS 15.7.1 With Important Security Fixes

Thursday October 27, 2022 10:12 am PDT by
Apple today released iOS 15.7.1 and iPadOS 15.7.1, operating system updates that are designed for older iPhones and iPads unable to run iOS 16 and iPadOS 16. The updates are also available to those who have chosen not to update to iOS 16 at this time. The ‌iOS and iPadOS 15.7.1‌ updates can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General >...
iOS 16

Apple Stops Signing iOS 16.0.2 Following Release of iOS 16.0.3

Monday October 17, 2022 8:03 pm PDT by
Following the release of iOS 16.0.3 last week, Apple has stopped signing iOS 16.0.2, meaning it is no longer possible to downgrade an iPhone to iOS 16.0.2. This leaves iOS 16.0.3 and the iOS 16.1 beta as the only iOS 16 versions that are still being signed. Apple routinely stops signing older iOS releases over time in order to prevent users from downgrading to an outdated software version. ...
mixpanel ios 16 adoption

iOS 16 Adoption Outpaces iOS 15 Adoption in First Two Days

Wednesday September 14, 2022 3:23 pm PDT by
iOS 16 is installed on an estimated 11.6 percent of iPhones two days after it launched, according to data shared by analytics company Mixpanel. The iOS 16 update was released to the public on Monday morning, and the site's data is accurate as of 12:00 a.m. Eastern Time on Wednesday morning. When iOS 15 was released last year, it was installed on just 8.5 percent of devices at the two day...
iOS 16

Apple Stops Signing iOS 16 and iOS 16.0.1, Downgrading From iOS 16.0.2 No Longer Possible

Friday September 30, 2022 4:59 am PDT by
Following the launch of iOS 16.0.2 last Thursday, Apple has stopped signing iOS 16 and iOS 16.0.1, the two previously available versions that came out in mid-September. Since the two versions are no longer being signed, it is not possible to downgrade to those versions of iOS after installing iOS 16.0.2. Apple routinely stops signing older versions of software updates after new releases come ...
iOS 15 General Feature Green

Apple Releases iOS 15.7 and iPadOS 15.7 With Security Updates

Monday September 12, 2022 9:54 am PDT by
Alongside iOS 16, Apple has released new versions of iOS 15.7 and iPadOS 15.7. The iOS 15.7 update is aimed at those who are not able to upgrade to iOS 16, while iPadOS 15.7 is available while we wait for the launch of iPadOS 16 in October. The software updates can be downloaded on eligible iPhones over-the-air by going to Settings > General > Software Update. The iOS 15.7 and iPadOS...
ios 16 lock screen feature

iOS 16 Proves More Popular Than iOS 15 Was Last Year

Wednesday September 21, 2022 12:09 pm PDT by
iPhone users are adopting iOS 16 at a quicker pace than they adopted iOS 15 last year, according to updated data from analytics company Mixpanel. Nine days after launch, iOS 16 is installed on an estimated 23.26 percent of iPhones. 10 days after launch in 2021, iOS 15 was installed on just 19.3 percent of devices, as iPhone owners at the time seemed more reluctant to upgrade due to some...

Popular Stories

iOS 16

iOS 16.2 Expected to Launch in Mid-December With Several New Features

Sunday October 30, 2022 6:53 am PDT by
iOS 16.2, the next major update to the iOS 16 operating system, can be expected to launch in mid-December alongside iPadOS 16.2, reliable Bloomberg journalist Mark Gurman said today in his Power on newsletter outlining expectations for the remainder of 2022. The first beta of iOS 16.2 and iPadOS 16.2 was released for developers and public beta testers last week, so it's still early to...
apple silicon mac lineup wwdc 2022

Gurman: Apple Planning No New Mac Releases For Remainder of 2022

Sunday October 30, 2022 6:08 am PDT by
Apple is not planning to announce any new Macs in the remainder of this year, with all planned releases expected to take place in the first quarter of 2023, including updated versions of the MacBook Pro, Mac mini, and the Mac Pro, Bloomberg's Mark Gurman said today. Writing in his latest Power On newsletter, Gurman said Apple has decided to wait until next year to announce new Macs,...
14 vs 16 inch mbp m2 pro and max feature 1

Rumor: New 14-Inch and 16-Inch MacBook Pros Delayed Until Next Year

Sunday October 30, 2022 4:57 am PDT by
Contrary to rumors that Apple will announce new 14-inch and 16-inch MacBook Pros powered with the yet to be announced M2 Pro and M2 Max chips in November, a new rumor has suggested Apple will instead release the new laptops next year. According to a post from the account "yeux1122" on the Korean blog Naver, citing a supply chain source, the updated 14-inch and 16-inch MacBook Pro models will ...
m2 macbook air pink

Apple Now Selling Refurbished M2 MacBook Air Models

Monday October 31, 2022 9:44 am PDT by
Apple today added refurbished M2 MacBook Air models to its online store, offering the machines at a discounted price for the first time. The M2 MacBook Airs first launched in July, and refurbished models have not previously been available. There are several variants available with different configurations and colors, but the base model MacBook Air with M2 chip, 8-core GPU, 8-core GPU, 8GB...
apple logo backlit mac

Backlit Apple Logo Could Make a Comeback on Future MacBooks

Monday October 31, 2022 8:33 am PDT by
Apple could be considering a return of the iconic backlit Apple logo on future MacBook models, if a newly published patent is anything to go by. Photo by Wes Hicks on Unsplash Once a common sight in coffee shops everywhere, the glowing emblem of an Apple logo featured on the lids of many Mac laptops launched in the early 2000s, but its demise in 2015 could turn out to be relatively...
mid 2017 iMac

Apple to Mark Several iMac Models as Obsolete Later This Month

Tuesday November 1, 2022 2:06 am PDT by
Apple plans to mark several 2013 and 2014 iMac models as obsolete at the end of this month, the company said in a memo obtained by MacRumors. In the memo, Apple said the 21.5-inch and 27-inch iMac from Late 2013, the Mid 2014 21.5-inch iMac, and the Retina 5K 27-inch iMac from late 2014 will be marked as obsolete on November 30, 2022. When marked as an obsolete product, the iMacs will no...
top stories 29oct2022

Top Stories: New iOS 16.1 Features, USB-C iPhone Confirmed, and More

Saturday October 29, 2022 6:00 am PDT by
October is drawing to a close with plenty to talk about in terms of new hardware and software releases from Apple, while we're also looking ahead with iOS 16.2 and future hardware. Read on below for all of the details on everything Apple released this week, including our early hands-on look at Apple's new iPads, plus a rumor about Apple's biggest-ever iPad and more! iOS 16.1 Released:...