iOS 27 update breaks NordVPN anti-phishing protection, company says
NordVPN says iOS 27's default-on Connectivity Assist breaks its anti-phishing protection by routing traffic outside VPN.
Connectivity Assist is designed to optimize Wi-Fi by supplementing slow or unreliable Wi-Fi connections with mobile data. It detects connection issues and redirects requests to mobile operator DNS servers. NordVPN said that when its anti-fraud protection blocks a phishing site, Apple may interpret the failed connection as a Wi-Fi problem and switch to mobile data, which sits outside the VPN's protection. That compromises the NordVPN tool, the company said.
NordVPN said the only current way to ensure full protection is to disable Connectivity Assistant so it cannot switch to mobile data when real-time protection blocks a website. Users can alternatively enable real-time protection only when using a VPN by disabling NordVPN's always-on option, but this still leaves them unprotected when using mobile data, albeit by choice.
"People are being made to choose between two things they shouldn't have to choose between, and there's no good way for us to fix it," Laura Tyrylyte, head of public relations at NordVPN, told TechRadar.
Tyrylyte said Apple could have addressed the issue before release. "Apple knew the feature interferes with DNS-based filtering before it shipped," she said. "Their own support page tells people running an ad blocker to switch Connectivity Assist for that network. Somebody spotted the conflict, it just didn't get fixed."
NordVPN stressed that users of Pi-hole, Firewalla and other DNS-based filtering tools had previously reported the same behavior, and that Cloudflare's WARP also stopped blocking malicious sites after the update. Apple engineers have suggested alternative solutions in forums, but these only work if users configure DNS settings themselves, Tyrylyte said.
"Deciding to treat deliberate filtering as a failed connection is a choice somebody made. They could have written it the other way: if a user-installed DNS service decides to resolve or block the query, leave that judgement alone," Tyrylyte said. "Instead, the problem got handed to users, who now need to end up fielding the support tickets for something we can't change," she added.
NordVPN said this is not the first time an Apple change to networking has compromised an iOS security feature. In 2023, vulnerabilities in Apple's VPN API disrupted NordVPN operations, according to the company. "Both times users ended up having to pick between an Apple feature and their own protection, and both times Apple was the only one who could have prevented that," Tyrylyte said. "Apple makes the call, and we find out what the call was when the release lands," she said.
Apple has yet to respond to a request for comment.