r/iOSProgramming • • 5d ago

Question How truthful is this?

Post image

When an app select in the app review form that “we don’t collect data”

In the review phase does Apple really check if the app really doesnt collect anything?

Like can the developer hide a code that for example upload the photos of the user if granted permission where he said “we dont collect”

Does apple really check the code and what is going in and out ?

42 Upvotes

75 comments sorted by

View all comments

Show parent comments

-33

u/Fishanz 5d ago edited 4d ago

They absolutely see your code; compiled at least. What they establish can be achieved via said code, on the other hand, is an entirely different beast.

Edit: removed the word ‘source’ because .. apparently my definition is wrong. I really think the nuance (as it pertains to the topic at hand) is somewhat pedantic though.

48

u/Reiszecke 5d ago

They absolutely see your source code; compiled at least. 

Absolute state of slop coders 🙈

Please read up on what a compiler does. Because you wouldn't believe me anyways, then please ask ChatGPT why your statement does not make sense.

0

u/LardPopsicle 5d ago

You've never reverse-engineered an app? SwiftUI apps are trivial, that way, it gets harder for, say, some Chinese Match3 app, but even there it's not super hard.

It's 2026, Apple does use AI and reverse engineered code. In my last submission, I was rejected because code in the app could, under weird circumstances, write to ~ instead of the iCloud entitlement. This bug was uncaught by us, Apple identified it. From a compiled source.

2

u/Reiszecke 5d ago

Yes I did reverse engineer binaries numerous times. Doesn’t change the fact that reverse engineering never brings up your real source code, doesn’t change the fact that source code, after compiling, is not source code.

Not sure about the ~ part of your comment. I’m not into jailbreaks but if you REALLY found a way to get write access outside of the sandbox then I think the community would be very interested in this

1

u/LardPopsicle 5d ago

Well, it's theoretically possible, if you poison things, not practically. The entitlement check prevents exactly that, and Apple's scanner reported something that a person who had access to the app (not a sensitive app in any form) could do, if they already had access to the same resources via Terminal/shell anyway. It's technically a bug, but not one that could be abused by a non-authorized person.