Apple emails disclosed in Epic trial show that 128M iPhone users, of which 18M were in the US and 55% in China, downloaded apps with XCodeGhost malware in 2015
The 2015 compromise of WeChat and dozens of other popular iOS apps via tainted Xcode downloads is now being re-litigated as evidence: emails surfaced in the Epic trial put the blast radius at 128 million iPhone users, 18 million of them in the US and 55 percent in China. The disclosure lands mid-trial, alongside other internal correspondence like Steve Jobs' 2007 email approving third-party apps, which together give the court and the public an unusually candid view of how Apple has governed the App Store.
That matters because App Store security — the claim that Apple's exclusive, curated distribution model protects users from exactly this kind of malware — is one of the pillars Apple is defending against Epic's challenge, a fight documented from Sweeney's early trial testimony through the broader trove of trial emails.
First-order effects
Apple's security argument in the Epic case now carries documented counterweight: 128 million users obtained malicious code through its reviewed store, undermining the 'closed ecosystem keeps you safe' premise at issue in court.
Second-order effects
Epic gains concrete material for its user-safety counter-narrative, while regulators and legislators weighing App Store alternatives get empirical proof that gatekeeping does not guarantee a malware-free supply chain.
Third-order effects
If the pattern holds, antitrust and platform-regulation debates will increasingly treat Apple's security rationale as testable rather than self-evident, raising the bar for any closed-distribution model to prove its safety premium with real incident data.
The trend: Trial-driven disclosure is converting Apple's private App Store history into public evidence that shapes how regulators judge the closed-ecosystem security trade-off.
New: as part of discovery in the Apple + Epic lawsuit, we've now seen previously unreported figures on what might be the biggest hack against iPhones ever on record. 128 million users, 18 million in the US. Apple seemingly didn't inform all victims https://www.vice.com/...
Seems the goal at Apple is to find bugs before ...the community!? 🧐😂 ...(naively?) thought the competition would be cybercriminals? You know the ones exploiting users🤷♂️ https://twitter.com/...
🤯 this is just mind-blowing. We can only guess what's happening on iOS. Based on amount of threat-activity that I see almost every day - it's the wild west. #transparency #FreeTheSandbox https://twitter.com/...
To be clear, we asked Apple if they notified victims, as they were discussing in the emails. The company pointed us to an FAQ it published at the time, that makes no mention of that. https://www.vice.com/...
NEW: Apple has finally revealed how many people downloaded malware that hackers snuck into thousands of apps in 2015. -128 million across the world, 18 million in the US. Compamy considered emailing them all, but it's unclear if it ever did. https://www.vice.com/...
This is the incident known as XCodeGhost, where someone put malicious code into a copy of XCode, which was then inserted in popular apps like WeChat and the Chinese version of Angry Birds 2. https://www.vice.com/...