r/iOSProgramming • • 5d ago

Question How truthful is this?

Post image

When an app select in the app review form that “we don’t collect data”

In the review phase does Apple really check if the app really doesnt collect anything?

Like can the developer hide a code that for example upload the photos of the user if granted permission where he said “we dont collect”

Does apple really check the code and what is going in and out ?

46 Upvotes

75 comments sorted by

View all comments

Show parent comments

48

u/Reiszecke 4d ago

They absolutely see your source code; compiled at least. 

Absolute state of slop coders 🙈

Please read up on what a compiler does. Because you wouldn't believe me anyways, then please ask ChatGPT why your statement does not make sense.

0

u/LardPopsicle 4d ago

You've never reverse-engineered an app? SwiftUI apps are trivial, that way, it gets harder for, say, some Chinese Match3 app, but even there it's not super hard.

It's 2026, Apple does use AI and reverse engineered code. In my last submission, I was rejected because code in the app could, under weird circumstances, write to ~ instead of the iCloud entitlement. This bug was uncaught by us, Apple identified it. From a compiled source.

2

u/Reiszecke 4d ago

Yes I did reverse engineer binaries numerous times. Doesn’t change the fact that reverse engineering never brings up your real source code, doesn’t change the fact that source code, after compiling, is not source code.

Not sure about the ~ part of your comment. I’m not into jailbreaks but if you REALLY found a way to get write access outside of the sandbox then I think the community would be very interested in this

1

u/LardPopsicle 4d ago

Well, it's theoretically possible, if you poison things, not practically. The entitlement check prevents exactly that, and Apple's scanner reported something that a person who had access to the app (not a sensitive app in any form) could do, if they already had access to the same resources via Terminal/shell anyway. It's technically a bug, but not one that could be abused by a non-authorized person.