This iOS bug might be stopping your VPN from keeping your browsing secure


An unpatched bug in iOS version 13.3.1 or later is preventing VPNs from working properly, potentially opening up users to data breaches.
The vulnerability, disclosed by ProtonVPN, does not terminate a connection when the user connects to a VPN, meaning that if kept active, unencrypted data could be transferred and possibly intercepted.
Unencrypted data can easily reveal personal details like IP address, location, or even expose users and the servers to cyber-attacks.
iOS vulnerability
“Most connections are short-lived and will eventually be re-established through the VPN tunnel on their own,” ProtonVPN explained. “However, some are long-lasting and can remain open for minutes to hours outside the VPN tunnel.”
Connections made after the VPN tunnel is activated remain secured and while most other OS terminate the existing connections, iOS for some reason keeps the old versions alive.
Researchers at ProtonVPN cited an example of Apple’s push notifications which uses a process to communicate with Apple’s servers for a long time. This connection does not get terminated automatically and may affect any service or app on the user’s iOS device.
While this bug might not impact an average user, “people in countries where surveillance and civil rights abuses are common,” are at high risk, ProtonVPN noted.
Due to security limitations, any third-party app or VPN cannot terminate these open connections on iOS. The report also suggests that Apple has acknowledged the VPN bypass vulnerability, and until it releases a solution, it recommends customers use an always-on VPN.
People who use other VPN apps can manually kill all the active connections by enabling and disabling Airplane mode after connecting to a VPN. While this workaround may kill most of the active connections, it may not be a 100% effective solution.
- Let us help you pick the best VPN options
Via: BleepingComputer
An unpatched bug in iOS version 13.3.1 or later is preventing VPNs from working properly, potentially opening up users to data breaches. The vulnerability, disclosed by ProtonVPN, does not terminate a connection when the user connects to a VPN, meaning that if kept active, unencrypted data could be transferred and…
Recent Posts
- Elon Musk says Grok 2 is going open source as he rolls out Grok 3 for Premium+ X subscribers only
- FTC Chair praises Justice Thomas as ‘the most important judge of the last 100 years’ for Black History Month
- HP acquires Humane AI assets and the AI pin will suffer a humane death
- HP acquires Humane AI assets and the AI pin may suffer a humane death
- HP acquires Humane Ai and gives the AI pin a humane death
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010