/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Apple emails disclosed in Epic trial show that 128M iPhone users, of which 18M were in the US and 55% in China, downloaded apps with XCodeGhost malware in 2015

As part of the trial against Epic Games, Apple released emails that show that 128 million users, of which 18 million were in the U.S. …

VICE Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

The Epic trial keeps functioning as a document leak: after a 2007 Steve Jobs email approving third-party apps surfaced last month, Apple's own correspondence now puts a hard number on an incident it had left vague. In 2015, developers of popular apps including WeChat built with a tampered copy of Apple's Xcode tool, and contemporaneous reporting counted WeChat among 39 known-compromised apps affecting hundreds of millions of users.

What's new here is Apple quantifying its own exposure — 128 million users downloaded malware-tainted apps, 18 million of them in the U.S., with China accounting for 55%. That matters because App Store curation and security are central to Apple's defense of its commission model against Epic, and this disclosure comes from Apple's own files rather than its critics.

First-order effects

  • Apple enters later rounds of the trial carrying a documented, company-acknowledged mass compromise that undercuts the 'walled garden keeps users safe' argument at the heart of its defense.
  • Epic gains a concrete exhibit showing that App Store review failed to catch malicious code distributed through one of the store's most heavily used regions — 55% of affected users were in China.

Second-order effects

  • Developers behind the 39 compromised apps, WeChat foremost among them, face renewed scrutiny over their 2015 build practices even six years later, since the disclosure reattaches the incident to named products.
  • The broader trove of trial disclosures — internal emails covering an 'iPhone nano' and App Store fee debates — forces Apple to litigate its history publicly, giving journalists and rivals a steady stream of material Apple never chose to publish.

Third-order effects

  • If litigation-driven discovery continues to expose platform holders' internal records, App Store security claims will increasingly be judged against documented incidents rather than marketing assurances — a structural shift toward evidence-based scrutiny of closed ecosystems.
  • The pattern points toward regulators weighing whether mandatory app review delivers the safety it advertises, since the largest recorded iOS compromise arrived through the developer toolchain, upstream of the review gate entirely.

The trend: Antitrust litigation is forcing Apple to disclose internal records that reframe the security-versus-control argument at the core of the App Store debate.

Discussion

  • @josephfcox Joseph Cox on x
    New: as part of discovery in the Apple + Epic lawsuit, we've now seen previously unreported figures on what might be the biggest hack against iPhones ever on record. 128 million users, 18 million in the US. Apple seemingly didn't inform all victims https://www.vice.com/...
  • @patrickwardle Patrick Wardle on x
    Seems the goal at Apple is to find bugs before ...the community!? 🧐😂 ...(naively?) thought the competition would be cybercriminals? You know the ones exploiting users🤷‍♂️ https://twitter.com/...
  • @ihackbanme Zuk on x
    🤯 this is just mind-blowing. We can only guess what's happening on iOS. Based on amount of threat-activity that I see almost every day - it's the wild west. #transparency #FreeTheSandbox https://twitter.com/...
  • @patrickwardle Patrick Wardle on x
    Want to infect more than 100M users? ...leverage the Apple App Store!? 🤔😭 https://twitter.com/... https://twitter.com/...
  • @krausefx Felix Krause on x
    Closed source SDKs, closed source dev tools, they all come in handy https://krausefx.com/... https://twitter.com/...
  • @k_sec Kurt Baumgartner on x
    walled gardens fail big when they fail https://twitter.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    To be clear, we asked Apple if they notified victims, as they were discussing in the emails. The company pointed us to an FAQ it published at the time, that makes no mention of that. https://www.vice.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Apple has finally revealed how many people downloaded malware that hackers snuck into thousands of apps in 2015. -128 million across the world, 18 million in the US. Compamy considered emailing them all, but it's unclear if it ever did. https://www.vice.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    This is the incident known as XCodeGhost, where someone put malicious code into a copy of XCode, which was then inserted in popular apps like WeChat and the Chinese version of Angry Birds 2. https://www.vice.com/...