Following the detection of 256 apps with an estimated 1 million total downloads for Apple devices that were extracting personally identifiable user information via private APIs prohibited by Apple, the Cupertino company has said that the affected apps have been removed from the Apple App Store.
Analytics service SourceDNA first reported the issue and said, “This is the first time we’ve seen iOS apps successfully bypass the app review process. But, based on what we learned, it might not be the last.”
SourceDNA found that the affected applications have been using the Youmi advertising SDK from China. The researchers believe that Youmi developers began experimenting with obfuscating a call to get the frontmost app name almost two years back.
The report further said that while Apple has been locking down private APIs, including blocking apps from reading the platform serial number in iOS 8, Youmi worked around this by enumerating peripheral devices, such as the battery system, and sending those serial numbers as a hardware identifier.
However, it added that the developers of these apps aren’t aware of this as the SDK is delivered in binary form, obfuscated, and user info is uploaded to Youmi’s server, not the app’s. It urged developers to stop using this SDK until this code is removed.
Apple issued a statement: “We’ve identified a group of apps that are using a third-party advertising SDK, developed by Youmi, a mobile advertising provider, that uses private APIs to gather private information, such as user email addresses and device identifiers, and route data to its company server. This is a violation of our security and privacy guidelines. The apps using Youmi’s SDK have been removed from the App Store and any new apps submitted to the App Store using this SDK will be rejected. We are working closely with developers to help them get updated versions of their apps that are safe for customers and in compliance with our guidelines back in the App Store quickly.”
Youmi has offered its “sincere apologies” in its ads after Apple removed the affected apps, Tech Times reported.


Australia Releases New National AI Plan, Opts for Existing Laws to Manage Risks
Apple Alerts EU Regulators That Apple Ads and Maps Meet DMA Gatekeeper Thresholds
YouTube Agrees to Follow Australia’s New Under-16 Social Media Ban
Apple Appoints Amar Subramanya as New Vice President of AI Amid Push to Accelerate Innovation
Coupang Apologizes After Massive Data Breach Affecting 33.7 Million Users
Nexperia Urges China Division to Resume Chip Production as Supply Risks Mount
Samsung Launches Galaxy Z TriFold to Elevate Its Position in the Foldable Smartphone Market
Morgan Stanley Boosts Nvidia and Broadcom Targets as AI Demand Surges
Trump Administration to Secure Equity Stake in Pat Gelsinger’s XLight Startup
TSMC Accuses Former Executive of Leaking Trade Secrets as Taiwan Prosecutors Launch Investigation
AI-Guided Drones Transform Ukraine’s Battlefield Strategy
Microchip Technology Boosts Q3 Outlook on Strong Bookings Momentum
Intel Boosts Malaysia Operations with Additional RM860 Million Investment
EU Prepares Antitrust Probe Into Meta’s AI Integration on WhatsApp
Wikipedia Pushes for AI Licensing Deals as Jimmy Wales Calls for Fair Compensation
Hikvision Challenges FCC Rule Tightening Restrictions on Chinese Telecom Equipment
Vietnam’s Growing Use of Chinese 5G Technology Raises Western Concerns 



