Researchers find 256 iOS apps using a third-party advertising SDK to collect users' personal info; Apple says it will ban them
Researchers find 256 iOS apps that collect users' personal info — Apps are “definitely the kind of stuff that Apple should have caught,” researcher says.
Context & Ripple Effects
This is an early entry point in a pattern that kept repeating: researchers finding data flows that Apple's own app review missed. Days after this ban announcement, a broader survey found popular apps routinely shipping email and location data to third parties, suggesting the 256 apps were symptoms rather than outliers.
The same playbook resurfaced years later — 24 iOS apps caught sending GPS and Wi-Fi identifiers to data monetization firms in 2018, then apps still transmitting identifying info despite Apple's ATT opt-outs in 2021. Each round raises the same question the researcher poses here: why does external discovery keep outrunning the App Store's gatekeeping?
First-order effects
- The 256 apps' developers face delisting from the App Store, with revenue cut off unless they strip or replace the offending advertising SDK.
- Apple's review process takes the reputational hit: the researcher's charge that these were 'definitely the kind of stuff that Apple should have caught' lands directly on the App Store's vetting claims.
Second-order effects
- Other app publishers using the same third-party SDK face an audit-or-die choice, since Apple has signaled it will police the SDK's behavior rather than wait for complaints.
- Google faces parallel pressure — its later removals of scam-ad and ad-fraud apps on Play (29 banned apps) show both stores converging on reactive bans as their enforcement tool.
Third-order effects
- If each scandal forces deeper inspection, store governance shifts from vetting apps at submission to policing the SDKs embedded inside them — the durable gap this story is an instance of.
- A recurring researcher-catches-what-review-missed cycle builds the case for regulatory oversight of app-store privacy enforcement rather than leaving it to platform self-policing.
The trend: App-store privacy enforcement is being driven less by platform review than by outside researchers repeatedly exposing data-collecting SDKs, pushing Apple and Google toward policing code libraries instead of just apps.