Apple to Alert Users Who Installed Apps Compromised by XcodeGhost

xcode-6Apple has added an XcodeGhost question and answer page to its Chinese website today that explains what the malware is, how some users may be affected and next steps the company is taking to ensure that developers and end users alike are protected against malicious software going forward.

Apple claims that it has no evidence to suggest that XcodeGhost has been used for anything malicious, such as the transmission of personally identifiable information, stipulating that the code is only able to deliver some general information about apps and system information.

Nevertheless, Apple says it is working closely with developers and will soon list the top 25 most popular apps impacted by XcodeGhost on its Chinese website. The company will also be alerting users to let them know if they have downloaded apps that could have been compromised. Many affected apps have since been updated and are no longer infected by XcodeGhost.

Relevant portions of the Apple FAQ for users:

How does this affect me? How do I know if my device has been compromised?
We have no information to suggest that the malware has been used to do anything malicious or that this exploit would have delivered any personally identifiable information had it been used.

We’re not aware of personally identifiable customer data being impacted and the code also did not have the ability to request customer credentials to gain iCloud and other service passwords.

As soon as we recognized these apps were using potentially malicious code we took them down. Developers are quickly updating their apps for users.

Malicious code could only have been able to deliver some general information such as the apps and general system information.

Is it safe for me to download apps from App Store?
We have removed the apps from the App Store that we know have been created with this counterfeit software and are blocking submissions of new apps that contain this malware from entering the App Store.

We’re working closely with developers to get impacted apps back on the App Store as quickly as possible for customers to enjoy.

A list of the top 25 most popular apps impacted will be listed soon so users can easily verify if they have downloaded the latest versions of these apps. After the top 25 impacted apps, the number of impacted users drops significantly.

Customers will be receiving more information letting them know if they’ve downloaded an app/apps that could have been compromised. Once a developer updates their app, that will fix the issue on the user’s device once they apply that update.

We’re working to make it faster for developers in China to download Xcode betas. To verify that their version of Xcode has not been altered, they can take the following steps posted at

iPhone, iPad and iPod touch users should also read our XcodeGhost FAQ to learn more about the malware and how to keep yourself protected.

Apple also outlined steps for developers to validate Xcode using Terminal on OS X.

Popular Stories

Apple Logo Top Half

Early iOS 26 Software Leak Uncovers Dozens of Upcoming Apple Features

Monday December 15, 2025 3:05 pm PST by
Software from an iPhone prototype running an early build of iOS 26 leaked last week, giving us a glimpse at future Apple devices and iOS features. We recapped device codenames in our prior article, and now we have a list of some of the most notable feature flags that were found in the software code. In some cases, it's obvious what the feature flags are referring to, while some are more...
apple beta 26 lineup

Apple Leak Confirms Work on Foldable iPhone, AirTag 2, and Dozens More Devices

Monday December 15, 2025 2:05 pm PST by
Last week, details about unreleased Apple devices and future iOS features were shared by Macworld. This week, we learned where the information came from, plus we have more findings from the leak. As it turns out, an Apple prototype device running an early build of iOS 26 was sold, and the person who bought it shared the software. The OS has a version number of 23A5234w, and the first...
iPhone Top Left Hole Punch Face ID Feature Purple

iPhone 18 Pro Features Leaked in New Report, Including Under-Screen Face ID

Tuesday December 16, 2025 8:44 am PST by
Next year's iPhone 18 Pro and iPhone 18 Pro Max will be equipped with under-screen Face ID, and the front camera will be moved to the top-left corner of the screen, according to a new report from The Information's Wayne Ma and Qianer Liu. As a result of these changes, the report said the iPhone 18 Pro models will not have a pill-shaped Dynamic Island cutout at the top of the screen....
iOS 26

iOS 26.3 Beta 1 Features: What's New So Far

Monday December 15, 2025 4:23 pm PST by
Apple is testing iOS 26.3, the next version of iOS 26 that will launch around January. Since iOS 26.3's testing is happening over the holidays, it is a smaller update with fewer features than we've seen in prior betas. We've rounded up what's new so far, and we'll add to our list with subsequent betas if we come across any other features. Transfer to Android Apple is making it simpler...
Apple Foldable Thumb

Leak Reveals Foldable iPhone Details

Monday December 15, 2025 9:09 am PST by
The first foldable iPhone will feature a series of design and hardware firsts for Apple, according to details shared by the Weibo leaker known as Digital Chat Station. According to a new post, via machine translation, Apple is developing what the leaker describes as a "wide foldable" device, a term used to refer to a horizontally oriented, book-style foldable with a large internal display....
iOS 26

iOS 26.4 and iOS 27 Features Revealed in New Leak

Friday December 12, 2025 10:56 am PST by
Macworld's Filipe Espósito today revealed a handful of features that Apple is allegedly planning for iOS 26.4, iOS 27, and even iOS 28. The report said the features are referenced within the code for a leaked internal build of iOS 26 that is not meant to be seen by the public. However, it appears that Espósito and/or his sources managed to gain access to it, providing us with a sneak peek...
apple iphone air battery pack

Apple Aims to Boost Popularity of iPhone Air 2 in Two Ways

Tuesday December 16, 2025 11:06 am PST by
We have been covering iPhone 18 Pro, iPhone 17e, and iPhone Fold details from The Information's report about future iPhone models, and next up is the iPhone Air 2. The report says that Apple aims to make the iPhone Air 2 more attractive in two ways. First, Apple is apparently considering adding a second rear camera to the device, which would resolve a key limitation. The current iPhone...
airpods max 2024 colors

AirPods Max 2 Likely to Offer These 10 New Features

Monday December 15, 2025 7:41 am PST by
Apple released the AirPods Max on December 15, 2020, meaning the over-ear headphones launched five years ago today. While the AirPods Max were updated with a USB-C port and new color options last year, followed by support for lossless audio and ultra-low latency audio this year, the headphones lack some of the features that have been introduced for newer generations of the regular AirPods and the ...
maxresdefault

Apple Developing iMac Pro With M5 Max Chip

Tuesday December 16, 2025 7:30 am PST by
Apple is developing a high-end iMac featuring the M5 Max chip, according to information from leaked internal software. Subscribe to the MacRumors YouTube channel for more videos. The finding comes from leaked kernel debug kit files used by Apple engineers. These kernel debug kit files enumerate unreleased Apple hardware by internal identifiers, such as codenames and platform names, and they...

Top Rated Comments

Analog Kid Avatar
134 months ago
The lesson to be learned is that you can't trust Chinese businesses, not without some research into their business practices anyway. But that's basic internet common sense isn't it?
I wouldn't pin this on any one country. Look at the mess Volkswagen just got themselves into. GM let faulty ignition switches keep killing people even after they knew it was happening. Japanese airbags.

Corruption can happen anywhere. It just so happens that a lot of low cost, under-regulated business is happening in China right now. Germany, the US, and Japan don't have that excuse, but they let it happen too. I think it's easy to fall back on stereotypes and say that the events in some countries are "unique" and in other countries it's "endemic" without thinking it through.

Edit: I just noticed you said "internet common sense", which I recognize as being different from actual common sense...
Score: 5 Votes (Like | Disagree)
mw360 Avatar
134 months ago
Apple should have caught the infected apps before approving them, but perhaps the main lesson to be learned here is to take great caution when downloading an app from a third-party server. In particular, download Apple apps from Apple only. This was easily avoidable and unwise developers created a huge mess.
How could apple have caught these apps? It's not like they simply failed to run a virus scan. The infection was completely unknown and doesn't do anything particularly dramatic to trigger alarm bells. There's virtually nothing to detect other than some fairly routine device polling.

Does this sound like a downplay to anyone?
Apps removed, users informed personally, C&C server taken down, devs notified. What's left for Apple to do, run around with their pants on their heads?
Score: 4 Votes (Like | Disagree)
Analog Kid Avatar
134 months ago
Apple really didn't think their security through.
I think that's a bit unfair. Apple software is remarkably secure, and they do take a lot of proactive steps to keep it that way. Sandboxing, code signing, GateKeeper, App Store approvals, etc all get a lot of resistance when they come out, but have had a positive affect on security.

What bothers me a little bit is that they really don't respond quickly to outside reports of vulnerabilities until they threaten bad press. I almost think they think security through very carefully, and have many very competent people focused on the problem, but suffer from some arrogance induced blindness.
Score: 4 Votes (Like | Disagree)
JonneyGee Avatar
134 months ago
Apple should have caught the infected apps before approving them, but perhaps the main lesson to be learned here is to take great caution when downloading an app from a third-party server. In particular, download Apple apps from Apple only. This was easily avoidable and unwise developers created a huge mess.
Score: 3 Votes (Like | Disagree)
Analog Kid Avatar
134 months ago
Why only the top N apps infected?! Shouldn't they list and take down all the apps infected? I don't think there's any reason to protect the developers here-- they made a grave error and should be accountable to it.

Why are they only sharing this information in China-- some of those apps are used globally.

Why did this take so long to provoke a reaction? When this report first came out 6 days ago, Apple should have sounded an internal alarm and gotten information within hours that would lead to action the same day.

I get that this isn't the end of the world, it's most likely a minor trojan that was mostly likely thwarted by Apple's security design. Still, it shouldn't be taken this casually. I don't care if the big picture impact is minimal-- we rely on App Store review to protect us from this nonsense, and it was circumvented because someone created a rogue version of an Apple branded product. I'd feel much more comfortable if Apple had moved on this more aggressively.
Score: 3 Votes (Like | Disagree)
Michaelgtrusa Avatar
134 months ago
Does this sound like a downplay to anyone?
Score: 3 Votes (Like | Disagree)