Apple Devices Contacting Chinese IPs

Ever since May 7th, 2025 my Apple devices have been contacting multiple Chinese IPs. They are the only devices on my network doing so and my Mac mini is not signed into any Apple Accounts. No other devices on the network are trying to reach these IPs. I’m in the US and my firewall is blocking these connections. What would be causing this?

iPhone 15 Pro Max, iOS 18

Posted on May 9, 2025 1:18 AM

Reply
Question marked as Top-ranking reply

Posted on Jun 6, 2025 3:46 PM

We’ve noticed similar unexplained connections to Chinese IP addresses starting after updating to iOS 18.5 (not necessarily connected events) on multiple Apple devices. Despite efforts such as monitoring traffic with tcpdump and Wireshark and resetting devices via DFU (without restoring from iCloud backup), the connections persist. We also used App Privacy Report but found no correlation between deleted apps and these connections.


This behavior appears isolated to Apple devices in our environment and is consistent across different networks, suggesting it originates from Apple’s software or services. Apple Support didn’t provide any clear explanations or solutions.


We believe it would be best to report these findings directly to Apple’s security team via their portal (https://security.apple.com/) before escalating to other authorities in the EU or US.


Here are some of contacted IPs:


122.246.2.7
223.109.243.5
101.71.175.135
113.141.163.10
42.56.77.227
113.142.186.8
116.153.82.194
101.71.164.197
180.97.241.196

Similar questions

21 replies
Question marked as Top-ranking reply

Jun 6, 2025 3:46 PM in response to botintaco

We’ve noticed similar unexplained connections to Chinese IP addresses starting after updating to iOS 18.5 (not necessarily connected events) on multiple Apple devices. Despite efforts such as monitoring traffic with tcpdump and Wireshark and resetting devices via DFU (without restoring from iCloud backup), the connections persist. We also used App Privacy Report but found no correlation between deleted apps and these connections.


This behavior appears isolated to Apple devices in our environment and is consistent across different networks, suggesting it originates from Apple’s software or services. Apple Support didn’t provide any clear explanations or solutions.


We believe it would be best to report these findings directly to Apple’s security team via their portal (https://security.apple.com/) before escalating to other authorities in the EU or US.


Here are some of contacted IPs:


122.246.2.7
223.109.243.5
101.71.175.135
113.141.163.10
42.56.77.227
113.142.186.8
116.153.82.194
101.71.164.197
180.97.241.196

May 19, 2025 11:59 PM in response to botintaco

Hi, I just came across your post – and I’m seeing the exact same behavior on my Apple devices (iPhones, MacBook, and iPads) in a completely different environment (I’m based in [your region, e.g. Japan]).

• Multiple connections to 183.131.xx.xx (CHINANET)

• Only from Apple devices

• HTTPS protocol

• Firewall (with GeoIP blocking) logs the attempts clearly

• Devices have different apps and setups


One of my devices is also not logged into any Apple ID, yet it still tries to make the same connections.


This doesn’t look like third-party apps. It’s happening on the OS or system service level.

I’ve blocked the IPs and captured logs, and I’m considering publishing a blog article about this unless Apple provides clarity.


Anyone else noticing the same?


May 12, 2025 4:58 AM in response to LD150

The firewall on my network was showing HTTPS requests to a bunch of Chinese IPs only coming from Apple devices. No VPNs present and not using private relay. No other devices on the network were contacting these addresses only Apple ones including my Mac mini which has no accounts on it so it appears the Apple devices are contacting that dns over https Apple domain by default and getting results in china for devices in the US.

May 9, 2025 1:54 AM in response to botintaco

Any report from a third-party app cannot be validated here in this forum.


If you encounter any challenges with third-party applications, the best course of action is to directly contact the app developer for further assistance. Here's a brief guide on how to do it:


  1. Identify the app developer.
  2. Visit their website or app store listing.
  3. Look for their contact information or support channels.
  4. Clearly describe the issue you are facing.
  5. Provide any necessary information they may need.
  6. Follow their instructions and provide feedback.
  7. Be patient and follow up if needed.


By reaching out to the app developer, you increase your chances of receiving accurate and personalized support for the challenges you're experiencing. To contact an App developer --> How to contact an app developer - Apple Support



May 12, 2025 8:17 AM in response to botintaco

Here is the brass tax. These IPs are from a CDN Apple uses in China, associated with chinacenter.com. Both users reporting the issue don't do business with Chinese sites or apps as evidenced by geo blocking of China. The big question is why is Apple, which makes big security and privacy boasts, connecting users to foreign networks? I block many other countries and China is the only one Apple appears to be sending connections to. For almost every plausible reason, it makes more sense for Apple to pull the data from Chinese sources once and cache it and distribute via CDNs regionally. For me, best case scenario is 250ms to China but only 8ms to Apple's US partners. If the intent is to exfiltrate data then it makes sense for Apple to make connections directly and quietly.


I feel Apple should explain. A small amount of transparency goes a long way.


May 24, 2025 11:03 AM in response to Eugene M Stoner

Eugene M Stoner wrote:

Why is a California based company sending data from user devices to a different country?

Because they can? Unlike China, the USA has no data sovereignty laws. Your data can be distributed all other the globe.


This is part of Apple's "Advanced Tracking and Fingerprinting Protection". The idea is that Apple will make your DNS requests securely via China so that the American personal information tracking and collection industry can't collect your browsing habits.


Jun 17, 2025 8:40 AM in response to botintaco

This is on all Apple devices on my network, then from Jun 8 of this year to now I've had over 5000 attempts at Telnet and other remote connection protocols trying to connect to my network. They've all been blocked but all in the same IP range. If it really is a CDN that is kind of insane so say hey we are private and going to block Meta and Google from getting your data, but the CCP has it now...

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Apple Devices Contacting Chinese IPs

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.