Mac App Store App 'Adware Doctor' Discovered Stealing User Browsing History [Update: Removed]

The number one top-selling paid Utilities app on the Mac App Store in the United States has been found to steal the browser history of anyone who downloads it, and is still on the App Store as of this article. A video posted in August gave a proof of concept to how the app "Adware Doctor" steals user data, and security researcher Patrick Wardle has now looked into the app and shared his findings with TechCrunch.


Adware Doctor's Mac App Store page says it will "keep your Mac safe" and "get rid of annoying pop-up ads." Besides being at the top of the Utilities chart on the Mac App Store, Adware Doctor is also currently the number five top paid app on the entire store in the U.S., behind apps like Notability and Apple's own Final Cut Pro.

In his blog post, Wardle explains that Adware Doctor withdraws sensitive user data -- predominantly any website you've searched for and browsed on -- and sends it to servers in China run by the app's makers. Apple was contacted a month ago -- around the time the original proof of concept video was shared online -- and promised it would investigate, but the $4.99 app remains on the Mac App Store.

TechCrunch gave an overview of Wardle's findings:

Wardle found that the downloaded app jumped through hoops to bypass Apple’s Mac sandboxing features, which prevents apps from grabbing data on the hard drive, and upload a user’s browser history on Chrome, Firefox, and Safari browsers.

Wardle found that the app, thanks to Apple’s own flawed vetting, could request access to the user’s home directory and its files. That isn’t out of the ordinary, Wardle says, because tools that market themselves as anti-malware or anti-adware expect access to the user’s files to scan for problems. When a user allows that access, the app can detect and clean adware — but if found to be malicious, it can “collect and exfiltrate any user file,” said Wardle.

Once the data is collected, it’s zipped into an archive file and sent to a domain based in China.

Towards the end of his post, Wardle discussed the ramifications of Adware Doctor and the privacy issue it presents, stating, "The fact that application has been surreptitiously exfiltrating users' browsing history, possibly for years, is, to put it mildly, rather f----- up!" The researcher also points out that Apple itself touts the Mac App Store as "the safest place to download apps for your Mac," which is often true.

Given the app violates numerous App Store Rules and Guidelines, namely including user consent on data collection, Wardle hopes that the increased spotlight on Adware Doctor's nefarious data collecting will make Apple take action. Even though Mac App Store customers who used the app would never be able to get their private browsing history back, the researcher says that Apple could begin to address the situation "by pulling the app and refunding all affected users."

Update 8:52 a.m. PT: Apple confirmed that Adware Doctor has been removed from the Mac App Store, along with the developer's other app "AdBlock Master."

Top Rated Comments

(View all)
Avatar
24 months ago
And that is what happens when you install a security software in a system that doesn't really need one.
Score: 62 Votes (Like | Disagree)
Avatar
24 months ago


Score: 31 Votes (Like | Disagree)
Avatar
24 months ago
Why does it always have to be a server in China?
Score: 22 Votes (Like | Disagree)
Avatar
24 months ago
Chinese software, who could have imagined it being a security issue!
Score: 21 Votes (Like | Disagree)
Avatar
24 months ago
Don't worry. Apple will always do the right thing.

Eventually. Either under penalty of the law, or due to public shaming.
Score: 20 Votes (Like | Disagree)
Avatar
24 months ago
Why does the Mac App Store still exist? It only has ****** scam apps and nothing that you actually need. Furthermore, you’re supposed to trust the App Store, because it’s “curated”, but then this kind of stuff happens. It would be better if Apple simply posted a “Gallery” of apps, like they do for safari extensions.
Score: 18 Votes (Like | Disagree)

Top Stories

Apple Officially Obsoletes First MacBook Pro With a Retina Display

Wednesday July 1, 2020 3:40 am PDT by
As expected, Apple's first MacBook Pro with a Retina display is now officially classed as "obsolete" worldwide, just over eight years after its release. In a support document, Apple notes that obsolete products are no longer eligible for hardware service, with "no exceptions." This means that any mid-2012 Retina MacBook Pro 15-inch models still out there that require a battery or other...

Kuo: iPhone 12 Models Won't Include Charger in Box, 20W Power Adapter Will Be Sold Separately

Sunday June 28, 2020 7:56 am PDT by
iPhone 12 models will not include EarPods or a power adapter in the box, analyst Ming-Chi Kuo said today in a research note obtained by MacRumors. This lines up with a prediction shared by analysts at Barclays earlier this week. Kuo said that Apple will instead release a new 20W power adapter as an optional accessory for iPhones and end production of its existing 5W and 18W power adapters...

Rosetta 2 Benchmarks Surface From Mac Mini With A12Z Chip

Monday June 29, 2020 7:48 am PDT by
While the terms and conditions for Apple's new "Developer Transition Kit" forbid developers from running benchmarks on the modified Mac mini with an A12Z chip, it appears that results are beginning to surface anyhow. Image Credit: Radek Pietruszewski Geekbench results uploaded so far suggest that the A12Z-based Mac mini has average single-core and multi-core scores of 811 and 2,781...

Apple's A12Z Under Rosetta Outperforms Microsoft's Native Arm-Based Surface Pro X

Monday June 29, 2020 10:31 am PDT by
Apple's Developer Transition Kit equipped with an A12Z iPad Pro chip began arriving in the hands of developers this morning to help them get their apps ready for Macs running Apple Silicon, and though forbidden, the first thing some developers did was benchmark the machine. Multiple Geekbench results have indicated that the Developer Transition Kit, which is a Mac mini with an iPad Pro chip, ...

New Mac Ransomware Found in Pirated Mac Apps

Tuesday June 30, 2020 11:44 am PDT by
There's a new 'EvilQuest' Mac ransomware variant that's spreading through pirated Mac apps, according to a new report shared today by Malwarebytes. The new ransomware was found in pirated download for the Little Snitch app found on a Russian forum. Right from the point of download, it was clear that something was wrong with the illicit version of Little Snitch, as it had a generic installer...

Developers Begin Receiving Mac Mini With A12Z Chip to Prepare Apps for Apple Silicon Macs

Monday June 29, 2020 5:43 am PDT by
As part of WWDC last week, Apple announced that it will be switching to its own custom-designed processors for Macs starting later this year. As part of this transition, the company is allowing developers to apply for a modified Mac mini with an A12Z chip and 16GB of RAM to develop and test their apps on a Mac with Arm-based architecture. As noted on Twitter and in the MacRumors forums, some...

Kuo: Apple to Launch 10.8-Inch iPad Later This Year, 8.5-Inch iPad Mini in 2021

Sunday June 28, 2020 9:04 am PDT by
Apple plans to launch a new 10.8-inch iPad in the second half of 2020, followed by a new 8.5-inch iPad in the first half of 2021, oft-reliable analyst Ming-Chi Kuo said today in a research note obtained by MacRumors. Kuo did not specify if the 10.8-inch iPad model will be a new version of the existing 10.2-inch iPad or the 10.5-inch iPad Air, but he has previously said that the 8.5-inch...

The New York Times Ends Apple News Partnership and Pulls All Articles

Monday June 29, 2020 11:17 am PDT by
The New York Times today announced that it is pulling out of Apple News, as the service does not "align with its strategy of building direct relationships with paying readers." Starting today, articles from The New York Times will no longer show up in the Apple News app. The news site says that Apple has given it "little in the way of direct relationships with readers" and "little control...

'iPhone 12 Pro' Models Could Be Capable of Shooting 4K Video at 120fps and 240fps

Monday June 29, 2020 3:57 am PDT by
Two new camera modes could be coming to some models of Apple's "iPhone 12," according to YouTube channel EverythingApplePro and Max Weinbach. Specifically, the video modes are said to include the ability to shoot 4K video at 120fps and 240fps. The new modes are thought to be coming to Apple's higher-end "iPhone 12 Pro" and "iPhone 12 Pro Max". Weinbach reportedly tore down the Camera app...

Leaker: Future iPhone Models to Come in 'Exquisite' Thinner Box

Wednesday July 1, 2020 1:57 am PDT by
Leaker L0vetodream this morning posted a tweet corroborating recent rumors that Apple's "iPhone 12" lineup won't come with EarPods or a charger in the box, adding that this will also eventually apply to the existing second-generation iPhone SE. L0vetodream also claims that future iPhone packaging will be "thinner" and "exquisite," which would make sense if Apple's handsets are set to come in ...