Apple has removed several apps from its store, following findings by security researchers that hundreds of iOS apps have access to users' personal data.
In a report published Sunday, researchers at security firm SourceDNA said they found 256 apps that violate Apple 's security guidelines by using software capable of collecting users' personal information, including their emails and device identification numbers.
SourceDNA did not name the affected apps, but said most were from developers in China. The source of the problem, the company said, was a software development kit (SDK) from Youmi, a Chinese advertising company. Youmi's advertising SDK had access to users' data, including email addresses and a list of downloaded apps, which it uploaded to its own server, according to Apple and SourceDNA.
SourceDNA researchers said it appears the app developers were unaware that the SDK had been used to collect personal information from their users. Apple prohibits developers from using application programming interfaces (APIs) that collect this kind of personal data, but the researchers said Youmi appears to have been putting it in its software almost two years ago, after its software passed Apple's initial review process.
Specifically, Apple confirmed that it had “identified the group of apps” using the SDK. The company said it removed the apps and is “working closely” with affected developers to help them upload their apps back to the store. Apple did not specify how many developers were affected or how many apps were removed.
The researchers said they found 256 apps — all together representing about 1 million downloads — that used the affected Youmi software. While 1 million downloads isn’t a huge number by App Store standards, SourceDNA says it’s concerning that other companies may have used similar tactics to hide “malicious behavior” in apps already on the App Store.
This marks the second time in a month that Apple has been forced to remove apps from the Chinese App Store. The company removed dozens of apps last month after researchers found they were infected with malware. The source of the malware was a widely distributed — but unofficial — version of Xcode used by many developers in China.

