I've noticed a curious oddity with some traffic sniffing from my apps on my iPhone. I've installed the ZAP Proxy CA certificate on the device, but I've noticed I can sniff some app traffic, and others I can't. This was apparent six months ago, but I've observed now even more of my suite failing to connect via the proxy, so my presumption is a trusted certificate is no longer trusted.
I'm aware there was an issue with iOS whereby a library permitted untrusted certificates to be used, but surely if I've installed a root CA, explicitly told the device its trusted, then I should be able to view all HTTPS traffic from the device?
Failing this, is it still possible to sniff HTTPS from the device via a proxy?