Update is in progress

A new unpatched “VPN Bypass” vulnerability uncovered in Apple iOS block VPNs to encrypt all the traffic that passes through the device.
The bug affected Apple’s iOS version 13.4, and it can be taking advantage of the cybercriminals to surveillance the user’s online activities also it leaks IP address and exposes the user’s data.
Luis, a security consultant from ProtonVPN discovered this VPN bypass vulnerability and reported to Apple under which is now working for the patch.
ProtonVPN reported this VPN Bypass vulnerability under 90 days responsible disclosure program, and the iOS community will get the patch on the next Apple security update, currently no patch available for this vulnerability.

How the iOS VPN bypass vulnerability works

Typically, when you connect to a virtual private network (VPN), the operating system of your device closes all existing Internet connections and then re-establishes them through the VPN tunnel.
A member of the Proton community discovered that in iOS version 13.3.1, the operating system does not close existing connections. (The issue also persists in the latest version, 13.4.) Most connections are short-lived and will eventually be re-established through the VPN tunnel on their own. However, some are long-lasting and can remain open for minutes to hours outside the VPN tunnel. One prominent example is Apple’s push notification service, which maintains a long-running connection between the device and Apple’s servers. But the problem could impact any app or service, such as instant messaging applications or web beacons.
The VPN bypass vulnerability could result in users’ data being exposed if the affected connections are not encrypted themselves (though this would be unusual nowadays). The more common problem is IP leaks. An attacker could see the users’ IP address and the IP address of the servers they’re connecting to. Additionally, the server you connect to would be able to see your true IP address rather than that of the VPN server.
Those at highest risk because of this security flaw are people in countries where surveillance and civil rights abuses are common.
Neither ProtonVPN nor any other VPN service can provide a workaround for this issue because iOS does not permit a VPN app to kill existing network connections.

Investigating the vulnerability

To investigate this issue, we used Wireshark to capture an iOS device’s network traffic. When you connect a device to VPN, you should only be able to see traffic between the device’s IP and the VPN server or local IP addresses (other devices on your local network). As the capture below shows, there is also direct traffic between the iOS device’s IP and an external IP address that is not the VPN server (in this case it’s an Apple server).

Unpatched “VPN Bypass” Vulnerability in Apple iOS = iOS device’s IP address = ProtonVPN server = Apple-owned IP address

How to mitigate the iOS VPN bypass vulnerability

Internet connections established after you connect to VPN are not affected. But connections that are already running when you connect to VPN may continue outside the VPN tunnel indefinitely. There is no way to guarantee that those connections will be closed at the moment you start a VPN connection.
However, we’ve discovered the following technique to be almost as effective:
1. Connect to any ProtonVPN server.
2. Turn on airplane mode. This will kill all Internet connections and temporarily disconnect ProtonVPN.
3. Turn off airplane mode. ProtonVPN will reconnect, and your other connections should also reconnect inside the VPN tunnel, though we cannot guarantee this 100%.

Alternatively, Apple recommends using Always-on VPN to mitigate this issue. This method requires using device management, so unfortunately it doesn’t mitigate the issue for third-party applications such as ProtonVPN.
This vulnerability was first reported by Luis, a security consultant and member of the Proton community According to him .
"We have been in contact with Apple, which has acknowledged the VPN bypass vulnerability and is looking into options to mitigate it. Until an update is available from Apple, we recommend the above workarounds."

Resources & References:


About Author :

Harsh Kiratsata

Harsh Kiratsata is an Expert in Networking and CyberSecurity Enthusiast too. He is CCNA certified and Gate qualified Scholar. Currently he's pursuing Masters in CYBER Security. He is active blogger and publisher of Cyber Security related articles on Cyber4All.