Apple's iOS App Store Suffers First Major Attack

Advertisement
By Reuters | Updated: 21 September 2015 09:32 IST
Apple Inc said on Sunday it is cleaning up its iOS App Store to remove malicious iPhone and iPad programs identified in the first large-scale attack on the popular mobile software outlet.

The company disclosed the effort after several cyber-security firms reported finding a malicious program dubbed XcodeGhost that was embedded in hundreds of legitimate apps.

It is the first reported case of large numbers of malicious software programs making their way past Apple's stringent app review process. Prior to this attack, a total of just five malicious apps had ever been found in the App Store, according to cyber-security firm Palo Alto Networks Inc.

Advertisement

The hackers embedded the malicious code in these apps by convincing developers of legitimate software to use a tainted, counterfeit version of Apple's software for creating iOS and Mac apps, which is known as Xcode, Apple said.

"We've removed the apps from the App Store that we know have been created with this counterfeit software," Apple spokeswoman Christine Monaghan said in an email. "We are working with the developers to make sure they're using the proper version of Xcode to rebuild their apps."

Advertisement

She did not say what steps iPhone and iPad users could take to determine whether their devices were infected.

Palo Alto Networks Director of Threat Intelligence Ryan Olson said the malware had limited functionality and his firm had uncovered no examples of data theft or other harm as a result of the attack.

Advertisement

Still, he said it was "a pretty big deal" because it showed that the App Store could be compromised if hackers infected machines of software developers writing legitimate apps. Other attackers may copy that approach, which is hard to defend against, he said.

"Developers are now a huge target," he said.

Researchers said infected apps included Tencent Holdings Ltd's popular mobile chat app WeChat, car-hailing app Didi Kuaidi and a music app from Internet portal NetEase Inc.

Advertisement

The tainted version of Xcode was downloaded from a server in China that developers may have used because it allowed for faster downloads than using Apple's U.S. servers, Olson said.

Chinese security firm Qihoo360 Technology Co said on its blog that it had uncovered 344 apps tainted with XcodeGhost.

Tencent said on its official WeChat blog that the security flaw affects WeChat 6.2.5, an old version of its popular chatting app, and that newer versions were unaffected. A preliminary investigation showed there had been no data theft or leakage of user information, the company said.

Apple declined to say how many apps it had uncovered.

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo K15 Pro Series With Active Cooling Fan Launched: See Price
  2. Lava Bold N2 Lite Arrives With a 5,000mAh Battery at This Price in India
  3. Vivo V70 FE Roundup: Launch Date, Expected Price in India, Specifications
  4. iQOO 15 Apex Edition Arrives in India as a Special Variant of iQOO 15
  5. Meta Launches First Prescription-Focussed Smart Glasses
  6. Realme C100 5G, C100i Price, Colours, Key Features Leak Ahead of Launch
  7. Gmail Rolls Out AI Inbox With Smart Prioritisation for These Users
  8. Disney Reportedly Interested in Buying Fortnite Maker Epic Games
  9. Oppo K15 Pro Key Specifications Confirmed Ahead of Launch in China
  10. Xiaomi 18 Pro Max Might Feature a More Efficient 200-Megapixel Sensor
  1. Gen Z Reportedly Dominates India’s Crypto Futures Market With 61 Percent Share
  2. Nvidia’s New DLSS 4.5 Update Brings AI-Powered 6X Multi-Frame Generation Feature
  3. Xbox Games Showcase Announced for June 7, Gears of War: E-Day to Get Deep Dive
  4. Apple's iOS 27 Update Expected to Include New ‘Alternative Words’ Keyboard Feature: Report
  5. OpenAI Raises $122 Billion in Latest Funding Round, Says Building Unified AI Superapp
  6. Bitcoin Price Rises to $69,000 as Ethereum Trades Near $2,100 Mark
  7. Nothing Reportedly Developing AI-Powered Smart Glasses, Earbuds as Part of Multi-Device Push
  8. Samsung Enables Blood Pressure Monitoring on Some Galaxy Watch Models in the US; Watch 9 Development Tipped
  9. Oppo K15 Pro+ and Oppo K15 Pro Launched With Active Cooling Fan, Up to 8,000mAh Battery: Price, Features
  10. Oracle to Reportedly Lay Off Thousands of Employees
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.