iOS 16 VPN Tunnels Leak Data, Even When Lockdown Mode Is Enabled

iOS 16 continues to leak data outside an active VPN tunnel, even when Lockdown mode is enabled, security researchers have discovered.

Lockdown Mode Feature
Speaking to MacRumors, security researchers Tommy Mysk and Talal Haj Bakry explained that ‌iOS 16‌'s approach to VPN traffic is the same whether Lockdown mode is enabled or not. The news is significant since iOS has a persistent, unresolved issue with leaking data outside an active VPN tunnel.

In August, it again emerged that third-party VPNs for iOS and iPadOS routinely fail to route all network traffic through a secure tunnel after they have been turned on – an issue that Apple has purportedly known about for years.

Typically, when a user activates a VPN, the operating system closes all existing internet connections and then re-establishes them through the VPN tunnel. In iOS, security researchers have found that sessions and connections established before the VPN is turned on are not terminated as one would expect, and can still send data outside the VPN tunnel while it is active, leaving it potentially unencrypted and exposed to ISPs and other parties.

According to a report from privacy company Proton, an iOS VPN bypass vulnerability had been identified in iOS 13.3.1, which persisted through three subsequent updates. Apple indicated it would add Kill Switch functionality in a future software update that would allow developers to block all existing connections if a VPN tunnel is lost, but this functionality does not appear to prevent data leaks as of iOS 15 and ‌iOS 16‌.

Mysk and Bakry have now discovered that ‌iOS 16‌ communicates with select Apple services outside an active VPN tunnel and leaks DNS requests without the user's knowledge:

Mysk and Bakry also investigated whether ‌iOS 16‌'s Lockdown mode takes the necessary steps to fix this issue and funnel all traffic through a VPN when one is enabled, and it appears that the exact same issue persists whether Lockdown mode is enabled or not, particularly with push notifications. This means that the minority of users who are vulnerable to a cyberattack and need to enable Lockdown mode are equally at risk of data leaks outside their active VPN tunnel.

‌iOS 16‌ introduced Lockdown mode as an optional security feature designed to protect the "very small number" of users who may be at risk of "highly targeted cyberattacks" from private companies developing state-sponsored spyware, such as journalists, activists, and government employees. Lockdown mode does not enable a VPN itself, and relies on the same third-party VPN apps as the rest of the system.

Due to the fact that ‌iOS 16‌ leaks data outside the VPN tunnel even where Lockdown mode is enabled, internet service providers, governments, and other organizations may be able to identify users who have a large amount of traffic, potentially highlighting influential individuals. It is possible that Apple does not want a potentially malicious VPN app to collect some kinds of traffic, but seeing as ISPs and governments are then able to do this, even if that is what the user is specifically trying to avoid, it seems likely that this is part of the same VPN problem that affects ‌iOS 16‌ as a whole.

It is worth noting that Apple only lists high-level features that activate when Lockdown mode is enabled, and Apple has not explicitly mentioned any changes that take place to affect VPN traffic. Nevertheless, as Lockdown mode claims to be an extreme protection measure, it seems like a considerable oversight that VPN traffic is a vulnerable point.

Related Roundups: iOS 16, iPadOS 16
Tag: VPN
Related Forum: iOS 16

Top Rated Comments

bevel Avatar
12 months ago
Come on Apple! How long is this going to take to fix? For a company that prides itself on privacy this is not good enough
Score: 49 Votes (Like | Disagree)
dmylrea Avatar
12 months ago
Looks like the phone that prides itself on privacy isn't so private after all.
Score: 38 Votes (Like | Disagree)
icanhazmac Avatar
12 months ago

an issue that Apple has purportedly known about for years
This is the most troubling part! Apple has the resources to fix anything they want to fix, why haven't they fixed this?
Score: 34 Votes (Like | Disagree)
SW3029 Avatar
12 months ago
**** Apple. There's a damn difference between real privacy and security and real good privacy and security marketing.
Score: 34 Votes (Like | Disagree)
cjbriare Avatar
12 months ago

vpn is no privacy tool, it is for connecting 2 networks secure. Don't try to change a feature to do a thing it is not meant to do...
what does the P stand for again?
Score: 28 Votes (Like | Disagree)
nt5672 Avatar
12 months ago

Come on Apple! How long is this going to take to fix? For a company that prides itself on privacy this is not good enough
Their pride is for marketing purposes, not real life.
Score: 22 Votes (Like | Disagree)

Popular Stories

Apple Wallet

Here's What's New in iOS 17 for Wallet and Apple Pay

Wednesday September 6, 2023 12:41 pm PDT by
In a WWDC 2023 video released in June, Apple outlined several improvements coming to the Wallet app and Apple Pay with iOS 17. The software update is currently in beta and will be released to the public later this year for the iPhone XS and newer. A major redesign for the Wallet app that was rumored ahead of WWDC never materialized, with only modest changes made in iOS 17. Apple Pay order ...
iPhone 15 Blue Three Quarters Perspective Camera Closeup Feature

Last-Minute iPhone 15 Report Reveals New Battery Life, Design, and Camera Details

Friday September 8, 2023 4:21 am PDT by
Bloomberg's Mark Gurman today shared his expectations for Apple's "Wonderlust" event, revealing several significant new features for the iPhone 15 and iPhone 15 Pro models. Gurman claims that the new titanium chassis of the iPhone 15 Pro models will be more durable, reduce weight by around 10 percent, and have a brushed effect, unlike the polished finish of the current devices that have...
iPhone 15 Pro Colors Mock Feature

iPhone 15 Pro to Start at 128GB Storage With 8GB of RAM — TrendForce

Thursday September 7, 2023 8:05 pm PDT by
Apple's upcoming iPhone 15 Pro and iPhone 15 Pro Max will have the same 128GB, 256GB, 512GB, and 1TB storage capacity options as the iPhone 14 Pro models, according to information shared today by Taiwanese research firm TrendForce. The research firm reiterated its claim that both iPhone 15 Pro models will be equipped with 8GB of RAM, compared to 6GB for the iPhone 14 Pro models. Increased...
iPhone 15 to Switch From Lightning to USB C in 2023 feature

Apple Retail Staff Drilled to Recommend iPhone 15 USB-C Charging Accessories at Point of Sale

Friday September 8, 2023 2:30 am PDT by
With Apple's iPhone 15 series launch potentially now just two weeks away, Apple retail employees are reportedly being drilled to emphasize to customers at the point of sale that the switch to USB-C means the new devices cannot be charged with existing Lightning charging cables that they may already own. When customers purchase a new iPhone 15 model, Apple staff will be trained to caution...
iPhone Ultra in Hand Feature

'iPhone 15 Pro Max' Name Reportedly Confirmed, 'iPhone 15 Ultra' Not Expected This Year

Friday September 8, 2023 11:29 am PDT by
Apple's highest-end iPhone this year will be named iPhone 15 Pro Max, instead of iPhone 15 Ultra, according to a report on Friday from Bloomberg's Mark Gurman. The other devices in the lineup will include the iPhone 15, iPhone 15 Plus, and iPhone 15 Pro. Gurman himself previously reported that Apple has considered Ultra branding for its highest-end iPhone, similar to the Apple Watch Ultra,...
iPhone 15 Pro Colors Mock Feature

iPhone 15 Pro Expected Next Week With These 12 New Features

Monday September 4, 2023 6:07 pm PDT by
Apple is expected to unveil four new iPhone 15 models at its event on Tuesday, September 12, and the devices will likely be available to pre-order starting Friday, September 15. All four models are rumored to be equipped with a USB-C port and the Dynamic Island, while many additional features are expected for the Pro models, including a titanium frame, customizable Action button, A17 Bionic chip, ...
Apple Watch Series 9 Pink Aluminum Feature

Gurman: Apple Watch Series 9 and Ultra 2 to Feature New Heart Rate Monitor, More Accurate Sensors, U2 Chip, and More

Friday September 8, 2023 4:31 am PDT by
The Apple Watch Series 9 and second-generation Apple Watch Ultra will offer several previously undisclosed features, Bloomberg's Mark Gurman claims. In a detailed report outlining his full expectations for Apple's "Wonderlust" event, Gurman said that the Apple Watch Series 9 and second-generation Apple Watch Ultra will offer various sensor and component upgrades, with a general "focus on...