Skip to main content
  1. Home
  2. Computing
  3. Features

Apple’s unsafe Mac App Store is simply inexcusable

Add as a preferred source on Google
adware doctor mac app store
Image used with permission by copyright holder

(in)Secure is a weekly column that dives into the rapidly escalating topic of cybersecurity.

Mac fans haven’t felt the love from Apple lately, but the problems go beyond a lack of new products. It’s become a matter of security.

Recommended Videos

A string of recent reports has shown certain apps in the Mac App Store were stealing data without user knowledge. These apps were supposedly vetted by Apple, and were popular, frequently-downloaded apps on the Mac App Store. Users had no reason to suspect the apps were malicious.

People’s trust in Apple has left them vulnerable, and it’s time Apple addressed it.

An app store legacy

The success of the iPhone has a lot to do with the app store’s curation. Each app available on iOS has an implied seal of approval from Apple. If you can download an app on your iPhone, it can be trusted. It’s safe. It’s a stark contrast from the Google Play store, which isn’t nearly as rigorous.

Adware Doctor app
Adware Doctor app Image used with permission by copyright holder

Much of the iOS App Store’s credibility has carried over to the Mac App Store, but apparently, it’s not deserved. As reported by ThreatPost, an app called Adware Doctor has been copying people’s browsing history from Chrome, Firefox, and Safari, and sending it off to a China-based domain, for currently unknown purposes. The app requests access to several questionable functions, though because of the trust people have put in the highly-rated app, they often approve the access.

Adware Doctor was in the number four spot in the “Top Paid” app list, right behind first-party software like Final Cut Pro.

The app was able to pass through the security controls of MacOS undetected, pull sensitive browsing history data, and download it as a zip archive. That flies in the face of Apple’s own data privacy policies. Of course, security breaches happen. That’s something every software company in the world deals with. The real problem is Apple’s failure to quickly remove the app.

The data theft was noted first by Patrick Wardle, founder of Mac security company Objective-See. According to him, Apple had been alerted about the suspicious app a month ago, and at the time of going public with his findings, had failed to take action.

Adware Doctor wasn’t just a small app that snuck through the fence. As ThreatPost points out, the app was listed in the number four spot in the “Top Paid” app list, right behind first-party software like Final Cut Pro. It was listed with endless five-star reviews, which were no doubt fake. It’s not hard to imagine why people would trust an app with such a high profile.

ALERT: ADWARE DOCTOR STEALING YOUR FILES PART 2

While Adware Doctor has since been removed, it took widespread media coverage for Apple to protect Mac owners who were actively having their data stolen. Apple’s failure to act quickly breaches the trust owners have put in Apple’s store.

It’s not just a few oddballs. It’s a trend

Adware Doctor isn’t the only app that’s been caught. In fact, an entire suite of apps from Trend Micro has been flagged for capturing the same data. That includes Dr. Antivirus, Dr. Cleaner, Dr. Unarchiver, and App Uninstall. Trend Micro initially denied the findings, but has since removed all such functions from the apps in attempts to get back into Apple’s good graces.

How could an app like this pass muster to begin with?

Malwarebytes said it has “taken as long as six months for a reported app to be removed.”

As it turns out, Adware Doctor was first accepted by Apple under the name of Adware Medic, which just happened to share its name with AdwareMedic app, a legitimate piece of software run by Malwarebytes. Trend Micro’s app was then removed, only to be re-accepted as Adware Doctor.

Not only did Apple approve an unsafe app, it approved it masquerading under the name of a proper app. That’s hardly top-tier espionage. If Apple could fall for that, what else might’ve pass by undiscovered?

Malwarebytes has been looking into that issue for years and reporting the appearance of junk software in Mac App Store. According to Malwarebytes, it’s sometimes “taken as long as six months for a reported app to be removed.”

With Apple’s renewed focus on the App Store in MacOS Mojave, we can only hope it takes back responsibility for cleaning up its mess. Yet with Apple’s attention squarely on iOS, we’re not getting our hopes up. If security isn’t a good enough reason to remember the Mac, then what is?

Luke Larsen
Former Senior Editor, Computing
Luke Larsen is the Senior Editor of Computing, managing all content covering laptops, monitors, PC hardware, Macs, and more.
OpenAI AI agents were linked to a cyberattack on RubyGems before the Hugging Face incident
Rogue AI concerns grow after OpenAI agents disrupt RubyGems in May attack
OpenAI logo on Microsoft surface

Artificial intelligence agents being tested by OpenAI were involved in a previously undisclosed cyberattack against RubyGems in May, an incident that is now raising uncomfortable questions about how much control humans really have over increasingly autonomous AI systems.

The attack overwhelmed RubyGems, a popular service used by software developers to publish and access Ruby packages, forcing operators to suspend new account registrations for four days. According to a report by The Wall Street Journal, OpenAI confirmed that its agents had been involved, but said they were using the platform to perform benign tasks and retrieve publicly available information during a training run.

Read more
AMD’s new budget CPUs could be a lifeline for cash-strapped PC builders
AMD Ryzen 5 5500F CPU

AMD has added two new six-core processors to its desktop lineup. The Ryzen 5 5500F brings six Zen 3 cores and 12 threads to the older AM4 platform for around $99, while the Ryzen 5 7500 moves to Zen 4 and AM5 for around $189, complete with integrated Radeon graphics.

The Ryzen 5 5500F arrives at an interesting time for budget PC builders. Putting together a current-generation system, or moving an existing PC to one, can get expensive quickly. An AM5 build requires a compatible motherboard and DDR5 memory, and RAM prices have risen sharply. For someone already running an AM4 system, the 5500F offers an inexpensive processor option without requiring a platform-wide replacement.

Read more
Leaked Lenovo Googlebook 15 specs suggest Google is targeting the premium laptop segment
The upcoming Googlebook could feature a 120Hz OLED display, an Intel Core Ultra processor, up to 32GB of RAM, and a surprisingly versatile selection of ports.
Googlebook

We recently got our first look at Lenovo's upcoming Googlebook, with leaked renders showcasing its design, port selection, and interface. Now, with just days left until Google's September 15 Googlebook preview event, a new leak has revealed the notebook's specifications.

Nothing like a bargain-bin Chromebook

Read more