We’ve noticed similar unexplained connections to Chinese IP addresses starting after updating to iOS 18.5 (not necessarily connected events) on multiple Apple devices. Despite efforts such as monitoring traffic with tcpdump and Wireshark and resetting devices via DFU (without restoring from iCloud backup), the connections persist. We also used App Privacy Report but found no correlation between deleted apps and these connections.
This behavior appears isolated to Apple devices in our environment and is consistent across different networks, suggesting it originates from Apple’s software or services. Apple Support didn’t provide any clear explanations or solutions.
We believe it would be best to report these findings directly to Apple’s security team via their portal (https://security.apple.com/) before escalating to other authorities in the EU or US.
Here are some of contacted IPs:
122.246.2.7
223.109.243.5
101.71.175.135
113.141.163.10
42.56.77.227
113.142.186.8
116.153.82.194
101.71.164.197
180.97.241.196