Scam and phishing protection on iOS 27: What you need to know

If you’ve recently updated your iPhone or iPad to iOS 27, you may have noticed that NordVPN’s real-time protection — shown as “Scam and phishing protection” in the app — isn’t blocking some ads, trackers, or malicious websites as expected. That’s because iOS 27 introduced Connectivity Assist, a new version of Wi-Fi Assist with expanded capabilities. If you had Wi-Fi Assist enabled before the update, Connectivity Assist is now on by default.

What causes the issue?

Connectivity Assist uses cellular data alongside Wi-Fi when it decides your Wi-Fi connection isn’t working well. When real-time protection blocks a domain, iOS can read that block as a potential connection problem.

Connectivity Assist then uses cellular data to look up the website address again. That request goes to your carrier’s DNS servers instead of NordVPN’s. If the lookup succeeds, the blocked site may load.

Every blocked domain is looked up separately, so the issue can affect not just phishing sites but also ads and trackers on otherwise normal pages. You stay connected to Wi-Fi throughout, and your settings still show that real-time protection is on, even though some requests bypass it entirely.

The issue only affects real-time protection when it’s set to “Always,” which allows the feature to work without an active VPN connection. If you’re connected to a NordVPN server, you’re not affected.

Other DNS-based tools are impacted too

The issue extends beyond NordVPN. Users of Pi-hole, Firewalla, and other DNS-based filtering tools reported the same behavior during the iOS 27 beta in July 2026, weeks before the public release. Our own tests show that Cloudflare’s WARP also stopped blocking malicious sites after the update.

Apple was aware the feature interferes with DNS-based filtering — its own support page tells users who run an ad blocker to switch Connectivity Assist off — but it shipped the feature as is. Apple engineers have also suggested workarounds in forums, but those workarounds can complicate the user experience and only work if people configure their DNS settings themselves.

This isn’t the first time an Apple networking change has undermined a security feature on iOS, and it isn’t the first time we’ve had to tell our users about it. In 2023, we published a post explaining why we had to ship a deliberately broken version of our “Stay invisible on a local network” feature. Apple’s VPN API had defects that left users choosing between protection and a working device. Apple confirmed those bugs existed and gave no timeline for fixing them.

How to stay protected

While we work on a permanent fix, you have two options to stay protected:

  1. 1.Turn off Connectivity Assist. Go to “Settings” > “Wi-Fi” and turn off “Connectivity assist.” Doing so stops your device from switching to cellular data when real-time protection blocks a site.
  2. 2.Use real-time protection only with a VPN. In the NordVPN app, tap the shield icon (labeled “Protect”), select “Only with VPN,” and connect to a NordVPN server.

For more information, check our Help Center article. Still having trouble? Contact our support team via 24/7 live chat in the NordVPN app.

Online security starts with a click.

Stay safe with the world’s leading VPN

Violeta Lyskoit | NordVPN

Violeta Lyskoit

Violeta is a copywriter who is keen on showing readers how to navigate the web safely, making sure their digital footprint stays private.