Skip to main content

Apple to alert affected users about major iOS security breach

App Store
arisara / Shutterstock.com
While Apple says it so far has no evidence suggesting that malware-infected apps discovered recently in its iOS store have stolen personal data or caused any other issues for users, it’ll nevertheless be contacting anyone who’s downloaded one or more of the infected apps with advice on what steps to take.

A Q&A posted by the Cupertino company on Tuesday aimed to ease the concerns of iPhone and iPad users who fear they may be using infected apps built with a modified version of Xcode, Apple’s app-building tool. The incident, which first hit the headlines over the weekend, is believed to be the most serious security breach in the App Store’s seven-year history.

Initial reports suggested around 40 apps were carrying the malware – among them Chinese messaging app WeChat and China-based Uber competitor Didi Kuaidi – though other reports have suggested a far higher number.

Apple responds

Responding to the issue in the Q&A, Apple said it’d removed infected apps that it’s aware of from its iOS App Store and is now blocking submissions of new apps that contain the malware.

“We’re working closely with developers to get impacted apps back on the App Store as quickly as possible for customers to enjoy,” the tech giant said, at the same time promising to release a list of the top 25 most popular apps impacted by the malware “so users can easily verify if they have downloaded the latest versions of these apps.”

The company confirmed it’ll be contacting customers who downloaded an app/apps that could have been compromised, adding, “Once a developer updates their app, that will fix the issue on the user’s device once they apply that update.”

Developers who created the malware-ridden software did so without realizing. Their mistake was to grab Xcode from a third-party site instead of from Apple’s own, as the version they downloaded had been altered to ensure apps created with the tool would incorporate the malicious software.

Some developers, mostly based in China, are known to head to third-party sites for the tool because they offer a faster download time. Apple is urging developers to stick with its own site for the tool, and is also promising to work on speeding up download times.

Security firm Palo Alto Networks (PAN) said the malware potentially impacts “hundreds of millions of users,” and described the malicious software as “a very harmful and dangerous malware that has bypassed Apple’s code review and made unprecedented attacks on the iOS ecosystem.”

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Everything you need to know about the massive Apple App Store outage
App Store on-screen illustration

Happy Wednesday evening, everyone! You're unwinding for the day, getting ready for a relaxing night, and ... you realize that the App Store and a bunch of other Apple services aren't working. Don't worry, you aren't alone.

What Apple services are down? When did the problems start? Is the outage still ongoing? Here's everything you need to know.
When did the App Store outage start?
According to DownDetector, reports of outages with the App Store flooded in a little after 6 p.m. ET. Reports appear to have spiked at over 6,000, indicating pretty widespread problems.

Read more
The 7 biggest features we expect to see in iOS 18
The home screen on the Apple iPhone 15 Plus.

Apple revealed that its Worldwide Developers Conference (WWDC) will take place on June 10. This is when we expect to see the next iteration of software across all of Apple’s products, including iOS 18.

From the sounds of it, we’re in for a big update with iOS 18, rumored to be one of the “biggest updates” yet. Here’s what we expect from Apple's next major iPhone update with iOS 18.
A more customizable home screen

Read more
This could be our first look at iOS 18’s huge redesign
An iPhone 14 Pro Max and iPhone 14 Pro standing upright on a desk.

While iOS 17 fell short on a visual overhaul, Apple is rumored to be working on an updated identity for its next iOS version. Previous reports have claimed that the upcoming iOS 18 will feature visionOS-like elements introduced on the Apple Vision Pro. A new report confirms this with a leaked image of the iOS 18 Camera app.

According to a report from MacRumors, the next version of the Camera app could feature visionOS-style design elements. It is based on an iPhone frame template that the publication received from an anonymous source who claimed to have received it from an iOS engineer. It is said to have been included as part of the Apple Design Resources for iOS 18.

Read more