Researchers Show How Apple's App Approval Process Can Be Beaten by Malicious Apps

NewImageResearchers from Georgia Tech submitted to the App Store and received approval for a malicious app, according to Technology Review. The researchers submitted an innocuous app that included inactive malware-type code hidden from Apple's app approval system.

When downloaded onto a test device after the app was approved, the app 'phoned home' and gained a variety of abilities that compromised the host phone.

This malware, which the researchers dubbed Jekyll, could stealthily post tweets, send e-mails and texts, steal personal information and device ID numbers, take photos, and attack other apps. It even provided a way to magnify its effects, because it could direct Safari, Apple’s default browser, to a website with more malware.

The researchers, including Long Lu, a Stony Brook University researcher who was part of the team at Georgia Tech, only put the app on the App Store very briefly and it was not downloaded by anyone other than research team members.

The team said that using monitoring code built into the app, they determined that Apple's app approval team only ran the app for a few seconds and that malicious code was not discovered by Apple's team. "The message we want to deliver is that right now, the Apple review process is mostly doing a static analysis of the app, which we say is not sufficient because dynamically generated logic cannot be very easily seen," said Lu.

Apple spokesman Tom Neumayr told Technology Review that the company made some changes to the iOS operating system in response to the paper, though he did not specify what the changes were.

Top Rated Comments

Shrink Avatar
138 months ago
I've come to a conclusion that all these analysts / researchers lack any thrill in their lives ..all they want to see is apple or any other company fail ..
I don't understand how pointing out a flaw that can be fixed represents a desire to see Apple fail.:confused:
Score: 12 Votes (Like | Disagree)
rmwebs Avatar
138 months ago
Sorry, I thought this was already public knowledge. Any app developer can embed malicious code, then have it 'turn on' at a specific time. There is no code check, Apple only launch the app - they never get a copy of the source code of each app so have no way of knowing what's inside of it.

The only way this will ever change is if the compilation of the apps is done on Apple servers.
Score: 11 Votes (Like | Disagree)
darster Avatar
138 months ago
Hats off to Georgia Tech!
Score: 8 Votes (Like | Disagree)
Dr McKay Avatar
138 months ago
Brace yourself. This Thread is about to turn into such a heated debate not even the Marshmallows will survive. :cool:
Score: 7 Votes (Like | Disagree)
JayCee842 Avatar
138 months ago
Fortunately with Apple's system - if something malicious is discovered it can be quickly pulled before harming anyone else.

Try getting the word out about a bad program and having it's website pulled. Much tougher as proven by all the spyware windows applications available.

Too bad this malicious malware wasn't discovered.
Score: 5 Votes (Like | Disagree)
fluchtpunkt Avatar
138 months ago
As long as they reported the issue to Apple privately long before dangling a treat in front of criminals.

Well, the fact that you can deactivate malicious code in your app until your app passed Apples review is well known to basically everyone who writes software.

Does anybody remember HiddenApps (https://www.macrumors.com/2013/03/11/hiddenapps-hides-stock-apps-iads-and-more-on-non-jailbroken-ios-devices/), the app that could be used to hide app icons on your device?
That app fetched a file from a webserver, if the file said "hide malicious code" the app showed some useless tricks on how to save battery. Once the app passed review the file said "do evil stuff" and the app executed the parts that would have lead to an rejection immediately.

There is no way to catch all evil code in an App. Not even access to the source code will make you a hundred percent safe. Because you have to read and understand it all to make a judgement. Ain't nobody got time for that.
Score: 4 Votes (Like | Disagree)

Popular Stories

iOS 17

10 New Things Your iPhone Can Do in Next Week's iOS 17.4 Update

Friday March 1, 2024 1:30 am PST by
Apple will this month release iOS 17.4, its biggest iPhone software update of the year so far, featuring a number of features and changes that users have been anticipating for quite a while. Below, we've listed 10 new things that your iPhone will be able to do after you've installed the update, which is projected to arrive by March 7. When the day arrives, be sure to check Settings ➝...
Apple Maps vs Google Maps Feature

Apple Maps vs. Google Maps: Which Is Better?

Friday March 1, 2024 7:10 am PST by
Apple Maps has been providing navigational guidance to Apple users for almost 13 and a half years now, and much has changed about the app in that time. However, according to data from Canalys, the overwhelming majority of iPhones in the U.S. still have Google Maps downloaded as an alternative to Apple Maps, which comes preinstalled on all iPhones. We want to hear from MacRumors readers. Which do...
Google maps feaure

Google Maps Finally Rolls Out Glanceable Directions

Wednesday February 28, 2024 2:07 am PST by
After more than a year since announcing the feature, Google Maps is finally rolling out glanceable directions on Android and iOS (via Android Police). The feature allows users to view turn-by-turn directions and a live ETA directly from their device's lock screen – information that was previously only visible when a phone was unlocked. Glanceable directions also work on the app's route...
iOS 18 Mock iPhone 16 Feature Gray

iOS 18 Rumored to Be Compatible With These iPhone Models

Tuesday February 27, 2024 6:31 am PST by
iOS 18 will be compatible with the iPhone XR, and thereby also the iPhone XS and iPhone XS Max models with the same A12 Bionic chip, according to a post on X today from a private account with a proven track record of sharing build numbers for upcoming iOS updates. The post was spotted by MacRumors contributor Aaron Perris, and it has since been deleted. However, this was likely because the...
M3 MacBook Air Feature

New MacBook Air Models Launching This March: 5 Features to Expect

Wednesday February 28, 2024 1:50 am PST by
The existing 15-inch MacBook Air arrived in June 2023, which is not that long ago in terms of Mac update cycles. However, Apple released the current 13-inch ‌MacBook Air back in June 2022. It is now the oldest Mac in Apple's current crop, having not been updated in 600 days. But rumors suggest that is unlikely to be the case for much longer. According to Bloomberg's Mark Gurman, Apple has...
apple tv plus banner

Apple TV+ Gains Over 50 Movies for a Limited Time

Friday March 1, 2024 6:29 am PST by
Apple TV+ today gained over 50 movies, adding to its back catalog of content for a limited time. The collection includes a large number of popular and classic titles. Subscribers can access the movies in a "Great Movies on Apple TV+" section in the Apple TV app. Some titles are also available in 3D. Movies in the collection include: 21 Jump Street 300 American Sniper Argo ...
airpods pro 2 pink

Apple Releases New Beta Firmware for AirPods Pro 2

Thursday February 29, 2024 11:41 am PST by
Apple today introduced a new beta firmware update for the AirPods Pro 2, both the USB-C and Lightning versions. The new firmware is version 6E188, up from the prior 6B34 firmware released in December. Apple does not often provide details or notes on what features might be included in the refreshed firmware, so it is unclear what's new. Note that this software is limited to developers at the...