Apple emails disclosed in Epic trial show that 128M iPhone users, of which 18M were in the US and 55% in China, downloaded apps with XCodeGhost malware in 2015
As part of the trial against Epic Games, Apple released emails that show that 128 million users, of which 18 million were in the U.S. …
Context & Ripple Effects
The Epic trial keeps functioning as a document leak: after a 2007 Steve Jobs email approving third-party apps surfaced last month, Apple's own correspondence now puts a hard number on an incident it had left vague. In 2015, developers of popular apps including WeChat built with a tampered copy of Apple's Xcode tool, and contemporaneous reporting counted WeChat among 39 known-compromised apps affecting hundreds of millions of users.
What's new here is Apple quantifying its own exposure — 128 million users downloaded malware-tainted apps, 18 million of them in the U.S., with China accounting for 55%. That matters because App Store curation and security are central to Apple's defense of its commission model against Epic, and this disclosure comes from Apple's own files rather than its critics.
First-order effects
- Apple enters later rounds of the trial carrying a documented, company-acknowledged mass compromise that undercuts the 'walled garden keeps users safe' argument at the heart of its defense.
- Epic gains a concrete exhibit showing that App Store review failed to catch malicious code distributed through one of the store's most heavily used regions — 55% of affected users were in China.
Second-order effects
- Developers behind the 39 compromised apps, WeChat foremost among them, face renewed scrutiny over their 2015 build practices even six years later, since the disclosure reattaches the incident to named products.
- The broader trove of trial disclosures — internal emails covering an 'iPhone nano' and App Store fee debates — forces Apple to litigate its history publicly, giving journalists and rivals a steady stream of material Apple never chose to publish.
Third-order effects
- If litigation-driven discovery continues to expose platform holders' internal records, App Store security claims will increasingly be judged against documented incidents rather than marketing assurances — a structural shift toward evidence-based scrutiny of closed ecosystems.
- The pattern points toward regulators weighing whether mandatory app review delivers the safety it advertises, since the largest recorded iOS compromise arrived through the developer toolchain, upstream of the review gate entirely.
The trend: Antitrust litigation is forcing Apple to disclose internal records that reframe the security-versus-control argument at the core of the App Store debate.