Skip to finding
important · Mobile — iOS

An ordinary iOS app can help a same-LAN peer hijack another app’s new TCP connection.

Affects

iOS, Apple’s mobile operating system for iPhone.

IP-options observations and port probing let the app infer enough shared state for the peer to race a forged SYN/ACK.

Detail and 2 sources

The result was demonstrated on an iPhone 15 running iOS 26.3.1, but only with a cooperating LAN injector and a new TCP flow lacking effective authentication above TCP.

Apple is working on a source-routing restriction, but no fixed iOS version has shipped.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026