Apple gets rid of infected apps that have sneaked into the App Store
Last week a major security breach was discovered in the Apple app store A major problem since it allowed normal operation of tools that contained lines of malicious code, capable of capturing not very relevant information from the user's terminal. Applications which, furthermore, are of paramount importance for a large number of users, since they are tools such as messaging WeChat , used by millions of users in ChinaAvoiding any greater evil, Apple has decided to withdraw them from the market
The problem was with XcodeGhost, an altered version of the tools for building apps on iOS that Apple distributes as Xcode And those alterations were lines of code with programs that infected all applications built with it Something that many developers used unintentionallywhen using the altered version, or in order to capture data that could be useful to improve your applications In any case, a problem that affected at least 39 applications in the Chinese market, with some important applications such as the aforementioned WeChat
Now a spokesperson for Apple has confirmed to Reuters that These apps with lines of malicious code have been removed.Also, they already work with the developers to recreate them with the original Xcode tool, without that there are new problems that compromise the security or privacy of users Of course, the real problem here lies in the security flaw of the hitherto prestigious admission process for new applications in App Store And they have let problems slip through the door without anyone realizing it until it was too late, affecting thousands of users.
At the moment Apple has not made any further statements, without informing how they will improve their security barriers in search of dangers that arrive in new applications or new updates. Of course, apparently one of the reasons developers used XcodeGhost, either intentionally or unknowingly, is because it was more quick and easy to download from other places rather than from the developer website of AppleA good starting point to improve things.
Those responsible for WeChat, one of the applications with the most users around the world, especially in China, they have already corrected the errors. Thus, they have managed to prevent Apple from removing their application from the App Store when launching a new one Nicely built update with Xcode, instead of the previous version where malware got into by using XcodeGhost A version that, apparently, did not cause problems for the user, since with this malware you could only find data such as the user's connections, the content of his clipboard and other similar issues. However, some security firms have discovered other more dangerous practical applications such as opening phishing dialogs (pretending to be official services that are not really), or the ability to open web addresses. Something that could be used to steal more important user data. At the moment it seems that the problem has already been fixed by Apple