iOS 27 treats a blocked site as a broken Wi-Fi network

Connectivity Assist, enabled by default in iOS 27, can read a deliberately refused connection as a failed network and move the request onto mobile data, past the filter that blocked it.

AppleThreat Staff
2 Min Read

A defence that someone deliberately switched on is being routed around by a setting they never chose, and the company raising the alarm says Apple’s own support pages already describe the workaround.

The setting is Connectivity Assist, a Wi-Fi aid that arrived with iOS 27 and ships enabled. It exists to rescue flaky wireless links, topping them up with cellular data.

There is a blind spot in that logic. When it decides a link is failing it also falls back to the carrier’s DNS servers, and a deliberately refused address looks like exactly the kind of trouble it hunts for. The request can then be handed to mobile data and travel to a destination the filter had already turned away.

Why a refusal looks like a fault

NordVPN says the casualties include its real-time anti-phishing and anti-fraud blocking. Administrators of Pi-hole, Firewalla and comparable resolvers report the same symptom, and Cloudflare’s WARP was seen letting hostile destinations through. Laura Tyrylyte, NordVPN’s head of public relations, told TechRadar the company had raised the conflict with Apple in advance.

Apple’s own guidance for affected networks tells subscribers using an ad blocker to switch Connectivity Assist off, and support threads from its engineers suggest reconfiguring DNS by hand – a remedy that presumes confidence most buyers lack. The two firms have clashed over iOS networking before: in 2023 NordVPN blamed reported weaknesses in Apple’s VPN interface for disruptions to its service. Apple had not answered questions when the report ran.

Share This Article