In rather shocking news, researchers have recently discovered a piece of iOS malware, XcodeGhost, in several apps in the Apple App Store. This is the sixth malware that has made its way into the official App store after LBTM, InstaStock, FindAndCall, Jekyll and FakeTor, according to Palo Alto Networks.
XcodeGhost can steal data and potentially trick people into providing personally identifiable information, explains Lookout Mobile Security. Its creators were able to sneak the malicious code into the apps without the app developers’ knowledge.
The malware made it through to the expanding list of apps that were published live to the Apple App Store. It removes information like the device’s name, country, and unique identifiers off the device. Palo Alto Networks says that it may also have the ability to push dialogue boxes to the iPhone or iPad’s screen, which could be used to steal username, password and other personal information (theoretically).
Furthermore, it may also be able to open websites in the mobile browser, which could be used for various malicious purposes including phishing and installing other potentially malicious software.
The affected apps include WeChat, CamCard, WinZip, CamScanner, PDFReader, WeLoop, SaveSnap and many others.
In an emailed statement, Apple told International Business Times:
“Apple takes security very seriously and iOS is designed to be reliable and secure from the moment you turn on your device. We offer developers the industry’s most advanced tools to create great apps. A fake version of one of these tools was posted by untrusted sources which may compromise user security from apps that are created with this counterfeit tool. To protect our customers, we’ve removed the apps from the App Store that we know have been created with this counterfeit software and we are working with the developers to make sure they’re using the proper version of Xcode to rebuild their apps.”


OpenAI Faces Scrutiny After Banning ChatGPT Account of Tumbler Ridge Shooting Suspect
Nvidia to Launch New AI Inference Processor to Boost OpenAI Performance
Meta Encryption Plan Sparks Child Safety Concerns Amid New Mexico Lawsuit
The Pentagon strongarmed AI firms before Iran strikes – in dark news for the future of ‘ethical AI’
Anthropic Refuses Pentagon Request to Remove AI Safeguards Amid Defense Contract Dispute
AI is already creeping into election campaigns. NZ’s rules aren’t ready
Nintendo Share Sale: MUFG and Bank of Kyoto to Sell Stakes in Strategic Unwinding
AWS Data Center in UAE Hit by Fire After Objects Strike Facility Amid Regional Tensions
U.S. Deploys Tomahawks, B-2 Bombers, F-35 Jets and AI Tools in Operation Epic Fury Against Iran
Trump Pushes Tech Giants to Build Power Plants to Offset AI Data Center Energy Costs
Federal Judge Blocks Virginia Social Media Age Verification Law Over First Amendment Concerns
Nvidia Earnings Preview: AI Chip Demand, Data Center Growth and Blackwell Shipments in Focus
Pentagon Weighs Supply Chain Risk Designation for Anthropic Over Claude AI Use
Hyundai Motor Plans Multibillion-Dollar Investment in Robotics, AI and Hydrogen in South Korea
Trump Orders Federal Agencies to Halt Use of Anthropic AI Technology
Hyundai Motor Group to Invest $6.26 Billion in AI Data Center, Robotics and Renewable Energy Projects in South Korea 



