Wednesday, July 29, 2026

Hidden Gambling Apps in Brazilian App Store

Marcus Mendes:

Last April, Brazilian officials notified Apple and Google over an alleged lack of age controls in betting apps on their respective app stores.

9to5Mac:

Brazilian users browsing the App Store rankings in categories such as Navigation, Travel, and Weather have noticed a growing number of poorly made games appearing among the top results, many of them featuring AI-generated illustrations of animals as their app icons. Many carry an AL age rating, making them available to users of all ages, including children.

As it turns out, these are so-called jacket apps, which are just a front for hidden betting and gambling apps.

[…]

The repository also includes explicit instructions intended to prevent the apps from being flagged as suspicious during App Store review. These include giving each app uniquely named startup and remote-configuration codes, making it harder for reviewers to identify them as part of the same group.

Ironically, the App Store’s own recommendation system appears to have little trouble grouping the apps together, as the “You Might Also Like” section on several of these apps points users toward other suspicious apps more frequently than they point to genuine apps.

John Gruber (Mastodon):

Obviously the main problem is that these apps disguise themselves Trojan Horse-style, and slip through App Store review undetected. I don’t think it’s reasonable to think App Store review could catch every attempt at this sort of thing though — if the horses are disguised well-enough, some of them are going to slip through. That’s actually fine.

I agree that it’s unreasonable to expect App Review to catch all those, but then Apple should not be pretending that it can. This was all obvious from day one. The public perception of App Review is completely at odds with what it actually can and does do.

But the first example 9to5Mac cites isn’t well disguised at all. What sense does it make that “PotatoPlot Puzzle” — a game featuring a rabbit potato farmer — is a weather app? How is that not a red flag right there?

[…]

I always mention that the point of such a squad shouldn’t be to make the App Store 100 percent scammer-free — which I believe is an impossible goal that would set the team up for failure. The point should be only to make the App Store free of successful scams. Focus on the most popular apps and the most lucrative apps.

The App Store is more than 18 years old. The idea of patrolling the top charts probably occurred to Apple before it even shipped. They just don’t want to do it.

Nick Lockwood:

Apple only took 24 hours to approve my iOS app update that crashed instantly on launch. Such a blessing to have that extra level of reliability and security that only a manual review process can provide 🙏

Incidentally, the crash was due to a missing dylib - something that could easily have been detected by the automated scan process, if only that scan were designed to protect users’ and developers’ interests instead of Apple’s.

Kyle Hughes:

There is simply no other way to maintain a modern, healthy software ecosystem without making sure that apps that have been around for 7 years and 20 major versions can’t get a build looked at within 48 hours. There’s no other way. Probably needs to be longer, honestly.

I had to file an Expedited Review Request because this update is a legitimate emergency. Four hours later, App Review rejected the build because they didn’t follow the first sentence of the testing instructions (which haven’t changed in 7 years). Back to Waiting for Review! There’s no other way.

Previously:

1 Comment RSS · Twitter · Mastodon


The irony here is that if a government decreed that they have to do this exact job because Apple has time and again proven to be unable, Apple would fight to the death to prevent that.

And they should because a government is not the same as a private corporation.

But I just really want to hear Apple's lawyers write page after page about why that shouldn't happen.

Leave a Comment