Some iPhone Apps Receive Mysterious Update 'From Apple'

(macrumors.com)

45 points | by tosh 3 hours ago

11 comments

  • F30 2 hours ago
    In the past, things like this used to be done for signing certificate rollovers.
  • eecc 36 minutes ago
    hmm, my money is on some actively used 0-day exploit that Apple is sealing shut before the CVE gets announced.

    By the looks of the app list, they seem to be apps and games that used to be popular and have fallen in disrepair and apps that are starved of maintenance attention.

    On the one hand it could be an exceptionally good example of "stewardship"; on the other hand, if this is true, what if authorities could later compel Apple to manipulate applications in some malign manner?

  • politelemon 1 hour ago
    Neither developers nor consumers should be comfortable with this, as this breaks the trust model and is extremely worrying. The site is of course downplaying it given its name, which is a huge shame.
  • gbil 43 minutes ago
    I saw this the other day in a couple of apps, I've checked other apps and didn't have that, did a quick check on HN frontpage and saw nothing and said wth I'll update to see if something changes in the app or there is a message. Got nothing, and didn't think more about it but I'm not sure why, is it the "trust in the process" thing or what?
  • ting0 34 minutes ago
    Has anyone ever done a proper security audit of VLC that is downloaded from the web? I don't trust it, and the fact that their releases on Github don't include binaries makes me trust it even less. Nobody is compiling VLC from source, and they don't provide any sort of provenance from the GH actions pipeline.
    • kykat 0 minutes ago
      All linux distros build VLC from source
    • ohhman11 25 minutes ago
      This seems utterly pointless to worry about. You're fucked either way if you trust VLC.
  • merelysounds 1 hour ago
    Speculation for fun: I always thought popular apps can use private apis or are handled in a special way by the OS itself. If yes, perhaps this is related.

    Then again I found no source for that - and some certificate rollover seems more likely.

  • hdgvhicv 1 hour ago
    Vast majority of change logs are along the lines of “implements to make things better”
  • NSUserDefaults 1 hour ago
    Could be a fix for per-device asset optimization that got messed up somehow.
    • Someone 1 hour ago
      FTA: “The update text is appearing on apps that have not been updated in some time, as well as apps that received recent updates, so it's not clear what the apps have in common.”

      ⇒ I think that’s unlikely. If some optimization got broken that produces results that bad that it has to be fixed, users would have noticed in those apps that “have not been updated in some time”.

  • charcircuit 37 minutes ago
    This sounds like a bug with the App Store app than a new update actually being installed.
  • swizz89 2 hours ago
    Is it a conspiracy, or just a bug in the app store? Nobody knows.