VPNs on iOS are "broken" and Apple doesn't seem to be doing anything to fix it

Connecting to a VPN in iOS settings
(Image credit: Shutterstock)

A leading security expert and blogger has claimed iOS VPNs are failing to secure users' data inside the VPN tunnel. 

Data leaks have allegedly occured over the past two years, with Apple knowing about it but not acting to fix the bug on its latest iOS versions.  

This might come as a shock for users looking to protect their online privacy with one of the best iPhone VPN services.  

iOS VPN users at risk

"VPNs on iOS are broken," wrote Michael Horowitz in a blog post who has been updating since May 25. 

He ran a total of four tests from his iPad, every time changing iOS version (15.4.1, 15.5 and 15.6), VPN provider (he tried with ProtonVPN, OVPN and Windscribe), VPN protocol (IKEv2, WireGuard and OpenVPN) and server network.

Even though at first the VPNs all seem working, a deeper inspection revealed the same disappointing result: the software breached devices' IP address and other personal data. "Data leaves the iOS device outside of the VPN tunnel. This is not a classic/legacy DNS leak, it is a data leak," he concludes. 

Put it simply, iOS VPNs seem not to be able to kill existing sessions before establishing a secure connection. Exactly what you would expect from one of the most secure VPN services. 

Data leak

(Image credit: Shutterstock/dalebor)

Apple was aware of the bug since 2020

This vulnerability affecting iOS VPNs is sadly nothing new. Swiss-based security firm Proton first reported on it in 2020, claiming the data leak started at least in iOS 13.3.1. 

Now, two years later and a few iOS updates after, Apple appears not to have managed to fix this risky bug yet. 

At the time, Proton pointed out a few work-arounds to the problem. These are activating the Always-on VPN option - something that Proton suggests would not work on third-party apps - enabling the kill switch on your VPN app, and/or using the Airplane Mode to terminate all your existing connections.  

However, Horowitz suggests that neither the kill switch option nor the Airplane Mode trick were successful when he tried them out during his tests. 

"To date, roughly five weeks later, Apple has said virtually nothing to me," he wrote on July 3, suggesting that for the silicon valley giant it would be really easy to run the same test and investigate the matter.

"At this point, I see no reason to trust any VPN on iOS. My suggestion would be to make the VPN connection using VPN client software in a router, rather than on an iOS device." 

TOPICS
Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
 laptop with warning symbol on desk
Experts predict malware may impact 39% of free Android VPNs by 2025 – but that's not the only worry
Someone checking their credit card details online.
Apple forced to patch iOS and macOS security flaw that could have leaked your private info
A VPN runs on a mobile phone placed on a laptop keyboard
Major new online tunneling vulnerability could put millions of devices at risk
Laptop with binary computer code and India flag on the screen
VPNs are disappearing from India's app stores – and a 2022 law may be the culprit
Vector illustration of the word Censored in a glitch distorted style
Google, Apple, and internet restriction – how Big Tech is making censorship "much worse" according to experts
Actalis SSL encryption
Apple is right not to bow down to the UK government's encryption backdoor request - but users should still be angry
Latest in VPN Privacy & Security
PrivadoVPN running on an iPhone during TechRadar's VPN tests
Why PrivadoVPN Free is still a stellar option for streaming
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
PrivadoVPN running on an iPhone during TechRadar's VPN tests
Why PrivadoVPN Free is still the best free VPN for streaming
Homepage of CloudFlare website on the display of PC, url - CloudFlare.com.
"Network blocking is never going to be the solution" – Cloudflare slams anti-piracy tactics
Panels at RightsCon 2025 during a press briefing about the latest Access Now report of internet shutdowns
2024 was the worst year on record for internet freedoms – again
Vector illustration of the word Censored in a glitch distorted style
Google, Apple, and internet restriction – how Big Tech is making censorship "much worse" according to experts
Latest in News
Google Gemini Robotics
Gemini just got physical and you should prepare for a robot revolution
Lilo & Stitch Official Trailer
Stitch crashes into earth and steals our hearts with the first trailer for the live-action Lilo & Stitch
GTA 5
GTA Online publisher Take-Two is gunning for a black market that’s basically heaven for cheaters
Y2K cast looking shocked
Y2K has a streaming release date on Max, so you can witness the technology uprising at home
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'