27 March 2020

Unpatched iOS bug prevents VPN apps from encrypting all traffic


Unpatched iOS bug prevents VPN apps from encrypting all traffic

A bug in Apple’s recent iOS releases, including the latest iOS 13.4 version, prevents VPN applications from encrypting all traffic. The vulnerability was discovered by a member of the Proton community in iOS 13.3.1, and though Apple is aware of the issue it has yet to release a patch.

Affected versions of iOS fail to close existing internet connections when a user connects to a VPN. Typically, when VPN is opened, the device’s operating system should close all existing internet connections and reestablish them through a VPN tunnel. Apparently, this process is not occurring in recent versions of iOS.

“Most connections are short-lived and will eventually be re-established through the VPN tunnel on their own. However, some are long-lasting and can remain open for minutes to hours outside the VPN tunnel,” Proton explained.

“One prominent example is Apple’s push notification service, which maintains a long-running connection between the device and Apple’s servers. But the problem could impact any app or service, such as instant messaging applications or web beacons,” the team added.

The long-lasting connections could potentially expose a user’s data, or reveal their true IP address rather than that of the VPN server.

Proton says that neither ProtonVPN nor any other VPN service can provide a workaround for this issue as iOS does not allow a VPN app to kill existing network connections.

Until the patch is available, Apple recommends using Always-on VPN to mitigate this issue.

Back to the list

Latest Posts

Cyber Security Week in Review: April 19, 2024

Cyber Security Week in Review: April 19, 2024

In brief: the LabHost PhaaS platform shut down, Russian military hackers attacked critical infrastructure in the US and Europe, and more.
19 April 2024
Ukrainian military personnel targeted via messaging apps and dating sites

Ukrainian military personnel targeted via messaging apps and dating sites

The threat actor employs a range of software in their malicious activities, including both commercial programs and  open-source tools.
18 April 2024
Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

This marks the first time Russian nation-state hackers have posed a direct threat to critical infrastructure in Western countries.
18 April 2024