/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Apple emails disclosed in Epic trial show that 128M iPhone users, of which 18M were in the US and 55% in China, downloaded apps with XCodeGhost malware in 2015

Lorenzo Franceschi-Bicchierai / VICE :

VICE Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

The 2015 compromise of WeChat and dozens of other popular iOS apps via tainted Xcode downloads is now being re-litigated as evidence: emails surfaced in the Epic trial put the blast radius at 128 million iPhone users, 18 million of them in the US and 55 percent in China. The disclosure lands mid-trial, alongside other internal correspondence like Steve Jobs' 2007 email approving third-party apps, which together give the court and the public an unusually candid view of how Apple has governed the App Store.

That matters because App Store security — the claim that Apple's exclusive, curated distribution model protects users from exactly this kind of malware — is one of the pillars Apple is defending against Epic's challenge, a fight documented from Sweeney's early trial testimony through the broader trove of trial emails.

First-order effects

  • Apple's security argument in the Epic case now carries documented counterweight: 128 million users obtained malicious code through its reviewed store, undermining the 'closed ecosystem keeps you safe' premise at issue in court.

Second-order effects

  • Epic gains concrete material for its user-safety counter-narrative, while regulators and legislators weighing App Store alternatives get empirical proof that gatekeeping does not guarantee a malware-free supply chain.

Third-order effects

  • If the pattern holds, antitrust and platform-regulation debates will increasingly treat Apple's security rationale as testable rather than self-evident, raising the bar for any closed-distribution model to prove its safety premium with real incident data.

The trend: Trial-driven disclosure is converting Apple's private App Store history into public evidence that shapes how regulators judge the closed-ecosystem security trade-off.

Discussion

  • @josephfcox Joseph Cox on x
    New: as part of discovery in the Apple + Epic lawsuit, we've now seen previously unreported figures on what might be the biggest hack against iPhones ever on record. 128 million users, 18 million in the US. Apple seemingly didn't inform all victims https://www.vice.com/...
  • @patrickwardle Patrick Wardle on x
    Seems the goal at Apple is to find bugs before ...the community!? 🧐😂 ...(naively?) thought the competition would be cybercriminals? You know the ones exploiting users🤷‍♂️ https://twitter.com/...
  • @ihackbanme Zuk on x
    🤯 this is just mind-blowing. We can only guess what's happening on iOS. Based on amount of threat-activity that I see almost every day - it's the wild west. #transparency #FreeTheSandbox https://twitter.com/...
  • @patrickwardle Patrick Wardle on x
    Want to infect more than 100M users? ...leverage the Apple App Store!? 🤔😭 https://twitter.com/... https://twitter.com/...
  • @krausefx Felix Krause on x
    Closed source SDKs, closed source dev tools, they all come in handy https://krausefx.com/... https://twitter.com/...
  • @k_sec Kurt Baumgartner on x
    walled gardens fail big when they fail https://twitter.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    To be clear, we asked Apple if they notified victims, as they were discussing in the emails. The company pointed us to an FAQ it published at the time, that makes no mention of that. https://www.vice.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Apple has finally revealed how many people downloaded malware that hackers snuck into thousands of apps in 2015. -128 million across the world, 18 million in the US. Compamy considered emailing them all, but it's unclear if it ever did. https://www.vice.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    This is the incident known as XCodeGhost, where someone put malicious code into a copy of XCode, which was then inserted in popular apps like WeChat and the Chinese version of Angry Birds 2. https://www.vice.com/...