important · Mobile — iOS
An ordinary iOS app can help a same-LAN peer hijack another app’s new TCP connection.
Affects
iOS, Apple’s mobile operating system for iPhone.
IP-options observations and port probing let the app infer enough shared state for the peer to race a forged SYN/ACK.
Detail and 2 sources
The result was demonstrated on an iPhone 15 running iOS 26.3.1, but only with a cooperating LAN injector and a new TCP flow lacking effective authentication above TCP.
Apple is working on a source-routing restriction, but no fixed iOS version has shipped.
Sources
Research[2609.09345] Cross User/App Network Attacks - Hijacking TCP Connections and DNS Cache Poisoning via a Malicious User/App (Extended Version)ResearchCross User/App Network Attacks — Hijacking TCP Connections and DNS Cache Poisoning via a Malicious User/App (Extended Version) (This is an extended version of the ACM CCS 2026 paper by the same title, DOI 10.1145/3830454.3846608)