Skip to content
DnsLister Forum

Where domain hunters compare notes

NordVPN says an iOS 27 feature can retry blocked sites over cellular data, potentially bypassing DNS-based protection

NordVPN has identified an unusual interaction between iOS 27 and DNS-based filtering.

Its real-time protection can deliberately block a connection to a malicious or fraudulent website. But according to NordVPN, iOS 27’s Connectivity Assist may interpret that failed request as a sign that the Wi-Fi connection is having problems.

The operating system can then switch the request to mobile data and the mobile operator’s DNS, potentially putting that connection outside the protection that originally blocked it.

What makes this easy to miss is that Connectivity Assist is enabled by default.

NordVPN says similar behavior has been reported with Pi-hole, Firewalla, and other DNS-based filtering products. It also says Cloudflare WARP stopped blocking malicious sites following the update.

For now, NordVPN recommends disabling Connectivity Assist if users want its real-time protection to work as intended. Another option involves changing how its “always on” protection is used, although that comes with a protection gap on mobile data.

The findings are based on NordVPN’s investigation and reports it cited involving other tools. Apple had not publicly responded to the report at the time of the supplied source.

The key setting is enabled by default. Here’s the technical explanation, NordVPN’s workaround, and the other DNS tools reportedly affected:

https://www.technadu.com/ios-27-nordvpn-issue-affects-real-time-phishing-protection/638472/

The interesting design question is whether an operating system should distinguish an intentional security block from an actual connectivity failure before automatically choosing another network path.

Source: r/TechNadu · by /u/technadu

Leave a Reply

Your email address will not be published. Required fields are marked *