Search

Unpatched Bug in Recent iOS Versions Keeps VPN From Encrypting All Traffic

The bug restricts affected iOS versions from closing all existing Internet connections.

Advertisement
Highlights
  • iOS 13.4 users are amongst the ones at risk due to the flaw
  • A security consultant of the Proton community reported its existence
  • iOS users can turn on and off airplane mode to manually fix the problem
Unpatched Bug in Recent iOS Versions Keeps VPN From Encrypting All Traffic

Apple is yet to release a fix for the security vulnerability, though a couple of workarounds do exist

Photo Credit: Justin Sullivan/ Getty Images North America/ AFP

An unpatched security vulnerability has been reported in recent iOS releases that prevents virtual private networks (VPNs) from being able to encrypt user traffic. The bug, which reportedly exists even in the latest iOS 13.4 update, could expose the personal data of users or provide their IP address details to attackers by bypassing the default VPN encryption. Apple hasn't provided any clarity on its fix, though you can expect an update to your iOS device in the coming days that would patch the security loophole.

Discovered initially by a security consultant of the Proton community, the VPN bypass vulnerability has affected iOS 13.3.1 and later versions, including iOS 13.4 that was rolled out just earlier this week. ProtonVPN has disclosed the issue through a blog post to make all VPN providers and end users aware of its scope.

A VPN is generally used to encrypt traffic, and once you enable a VPN on your device, its operating system typically closes existing Internet connections and re-establishes them through the VPN tunnel. However, the bug discovered in the recent iOS releases restricts the operating system from closing all existing Internet connections.

Although most Internet connections are short-lived and are likely to be re-established through the VPN tunnel, some are long-lasting and can remain active for even hours outside the tunnel. Apple's push notification service is one such example that maintains a long-running connect between the device and Apple's servers. This brings some major security concerns.

“The VPN bypass vulnerability could result in users' data being exposed if the affected connections are not encrypted themselves (though this would be unusual nowadays). The more common problem is IP leaks. An attacker could see the users' IP address and the IP address of the servers they're connecting to,” the ProtonVPN team writes in the blog post explaining the bug.

The team also underlines that users in countries where surveillance and civil rights abuses are common are at highest risk due to the security flaw. Moreover, VPN service providers can't provide a workaround from their end to fix the loophole since it exists at the operating system level.

That being said, affected iOS users can mitigate the VPN bypass vulnerability on their devices by turning on and off the airplane mode after connecting to a VPN service. This is likely to re-establish connectivity with existing Internet connections through the VPN tunnel.

Apple is already aware of the flaw and is expected to update iOS with a fix soon. Meanwhile, you can apply the airplane mode workaround to limit the problem to some extent. The iPhone maker also recommends its users to opt for the Always-on VPN method that requires device management software to encrypt all traffic through a VPN service.

Since iPadOS is also built on iOS, it would also have the same VPN bypass flaw and would be able to encrypt user traffic through the aforementioned workarounds.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Poco F7 5G India Launch Today: How to Watch, Expected Price and Features
  2. Vivo X200 FE Compact Smartphone Launched With 6,500mAh Battery
  3. Oppo K13x 5G With 6,000mAh Battery Launched in India: See Price
  4. Nothing Phone 3a Pro 5G Long Term Review: A Blend of Style, Speed, and Power
  5. Samsung Exynos 2500 SoC Unveiled Ahead of Next Galaxy Unpacked Event
  6. Tecno Spark Go 2 India Launch Date, Key Features Announced
  7. 'Ghost' Plume Found Beneath Oman May Explain India's Ancient Tectonic Shift
  8. Boat Airdopes Prime 701 ANC With Up to 50 Hours Battery Launched in India
  9. Kubera OTT Release Reportedly Revealed: Where to Watch Dhanush Starrer Movie Online?
  10. Vivo T4 Lite 5G India Launch Set for Today: Expected Price and Features
  1. Poco F7 5G Launch in India Today: How to Watch Livestream, Expected Price, Specifications
  2. ‘Ghost’ Plume Found Beneath Oman May Explain India’s Ancient Tectonic Shift
  3. Blue Origin’s Crewed Suborbital Launch Delayed Again Due to Weather Conditions
  4. Green Rooftops Could Help Cities Like Shanghai Filter Out Tons of Microplastics from Rainwater
  5. SpaceX to Launch Over 150 Memorial DNA Capsules into Orbit on Celestis’ Perseverance Flight
  6. Rubin Observatory to Unveil First Cosmic Images with World’s Largest Digital Camera
  7. The Gilded Age OTT Release: Where to Watch This HBO Original Series
  8. Cleaner (2025) OTT Release Date: When and Where to Watch it Online?
  9. Yugi Now Available for Streaming on Aha Tamil: Everything You Need to Know
  10. Samsung Exynos 2500 SoC With Up to 15 Percent Improved CPU Performance, Xclipse 950 GPU Launched
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »