Not just Facebook and Google: hardcore porn and real-money gambling apps openly abused Apple's 'Enterprise' program

8comments
Not just Facebook and Google: hardcore porn and real-money gambling apps openly abused Apple's 'Enterprise' program
Last week, news broke that Facebook and Google openly abused Apple's Enterprise Certificate program to get unprecedented access to private iPhone users' data. Facebook particularly used this loophole to gain root permissions which allowed the company to mine data about anything and everything on an iPhone, including private photos and videos, and Internet traffic that the company likely used to gain a competitive advantage over its rivals.

Today, we learn that it was not just Facebook and Google: dozens and dozens of hardcore pornography and real-money gambling apps used the same loophole to circumvent the App Store and bring apps to iPhones that would never have passed Apple's own rules.


Apple has been openly critical about other companies' security breaches (rightly so), but has itself enforced poor control over its own Enterprise Certificate program, which has made all sorts of different violations possible. The revelations come from a continued investigation by TechCrunch.

Recommended For You

And here is how it worked:

Apple runs an Enterprise Certificate program, which is originally designed for companies to distribute internal apps to their employees and their employees only. The policy for this program explicitly says that "You may not use, distribute or otherwise make Your Internal Use Applications available to Your Customers." Apple, however, has failed to properly enforce its own rules.


There seem to be two ways of exploiting the Enterprise program that are used. The first one uses Apple's lax standard for accepting new business to the program. It takes filling an online form, paying a one-time $300 fee to Apple and telling a couple of lies on the phone to register a new business that could then misuse the Enterprise Certificate to distribute forbidden applications to users. The second method actually piggybacks on a legitimate certificate issued to a company. It's not clear exactly how, but developers are able to get 'rogue certificates' from a legitimate company to sign their forbidden apps and make them available to the public. Such certificate codes are then sold on various Chinese marketplaces and you could have up to a dozen of different forbidden apps piggybacking on one legitimate certificate.

Some of these apps are not explicitly malicious and do not mind user data as aggressively as Facebook did with its Facebook Research VPN app, while some 'helper tool' apps would install tracking and adware codes.


Guardian Mobile Firewall security researcher Will Strafach said that all of that could have easily been prevented had there been more strict rules for registering a business under this program and proper audit. "Given the rampant abuse, it seems Apple could easily add stronger verification processes and more check-ups to the Enterprise Certificate program. Developers should have to do more to prove their apps’ connection with the Certificate holder, and Apple should regularly audit certificates to see what kind of apps they’re powering."

Apple has already removed some of these malicious apps, but many others remain out in the wild. The company has not yet provided an official response to this and we'll update you as soon as there is one.

Grab the Pixel 10 at Mint Mobile for $450 off

$349
$799
$450 off (56%)
Mint Mobile now sells the Google Pixel 10 with a massive $450 discount. The promo is available on select color variants with 128GB of storage. You also get a 12-month unlimited data plan for $180 instead of $360.
Buy at Mint Mobile

Pixel 10 Pro: now $475 off at Mint

$524
$999
$475 off (48%)
Grab the pro-grade, compact Pixel 10 Pro at Mint Mobile with a 12-month unlimited plan, and you can save a huge $475. The data plan comes with a discount, too: 50% off, to be exact.
Buy at Mint Mobile

The Pixel 10 Pro XL is $700 off at Mint right now

$499
$1199
$700 off (58%)
The high-end Gemini AI-enhanced Pixel 10 Pro XL is now available with a mind-blowing discount. You can now save $700 on the phone, plus 50% off unlimited 12-month plans.
Buy at Mint Mobile

The Pixel 10 Pro Fold is now $400 off

$1399
$1799
$400 off (22%)
The foldable Pixel 10 Pro Fold is another standout holiday offer. Right now, you can get the device for $400 off at Mint Mobile. On top of that, you save $180 on 12-month unlimited data plans.
Buy at Mint Mobile
Google News Follow
Follow us on Google News

Recommended For You

COMMENTS (8)

Latest Discussions

by 30zpark • 3
by RxCourier9534 • 13
FCC OKs Cingular\'s purchase of AT&T Wireless