Magazine

Apple Nixes Feature That Let Apps Bypass VPN

Posted on the 16 January 2021 by Thiruvenkatam Chinnagounder @tipsclear
Apple nixes feature that let apps bypass VPNApple nixes feature that let apps bypass VPN

Apple

Apple has reportedly removed a controversial MacOS feature in, amid mounting concerns from security researchers Big Sur 11.2 Beta 2 on Thursday. This feature was discovered during the first beta version of Big Sur 11.2 and allowed 53 of Apple's own apps to bypass security firewalls and security virtual private networksAccording to CNET's sister ZDNet.

The researchers argued that the feature known as the content filter exclusion list could have enabled malware attacks through unguarded entry points and could have compromised user identities. The list included 53 of Apple's own apps, whose inbound and outbound traffic was allowed to bypass Internet connection security tools such as third-party firewalls and VPNs. That list of apps included some of the most popular ones - App Store, Maps, and iCloud among them.

Everything Apple

CNET's Apple Report newsletter provides news, reviews, and advice about iPhones, iPads, Macs, and software.

Apple told ZDNet the list was temporary, and an Apple software developer later said the list was the result of a series of bugs in Apple apps that have since been fixed. After Big Sur 11.2 is released, all Apple apps will again be subject to firewalls and security tools and will be compatible with VPN apps, according to Apple.

The feature vulnerability was first discovered in October by a Big Sur 11.2 Beta 1 user.

Some Apple apps bypass some network extensions and VPN apps. For example, cards can access the Internet directly by bypassing all NEFilterDataProviders or NEAppProxyProviders

- Maxwell (@mxswd) 19th October 2020

The vulnerability remained open even after leaving the first beta phase of the product and was again noted on Twitter by security researcher Patrick Wardle.

In Big Sur, Apple decided to exempt many of its apps from being routed through the frameworks, which now require third-party firewalls to be used (LuLu, Little Snitch, etc.)

Q: Could this be used by malware (ab) to bypass such firewalls as well? 🤔

A: Apparently yes and trivially so 😬😱😭 pic.twitter.com/CCNcnGPFIB

- Patrick Wardle (@patrickwardle) November 14, 2020

A handful of standalone commercial VPN apps like Proton VPN and Mullvad say they weren't previously affected by the feature. Others, like Hide.Me, have offered their users instructions on possible workarounds.

Apple did not immediately respond to CNET's request for comment.

Apple nixes feature that let apps bypass VPNApple nixes feature that let apps bypass VPN

Back to Featured Articles on Logo Paperblog