Archive for August 18, 2026

Tuesday, August 18, 2026

New EU App Store Terms to Comply With DMA

Apple (developer, details, Hacker News, TechCrunch, The Verge, 9To5Mac):

These changes resolve Apple’s disagreements with the Commission over business terms and alternative distribution. They also reduce complexity by moving every developer that distributes apps in the EU to a single set of business terms.

[…]

The Core Technology Fee, a per-install fee for developers that achieve extraordinary scale, will be replaced by the Core Technology Commission, a simple 5 percent commission on digital transactions in apps distributed outside the App Store. The new terms also eliminate the initial acquisition fee and store services fee.

[…]

Under the updated terms, developers can now offer Apple In-App Purchase alongside alternative payment options, which had not previously been permitted in the EU.

[…]

Apple is also expanding who is eligible to operate an alternative app marketplace or distribute apps via the web in the EU.

[…]

Apple will continue to require every alternatively distributed app to go through Notarization[…]

Juli Clover:

Apple will charge a 26% fee for apps distributed through the App Store that use in-app purchase.

[…]

Apps in the App Store that use in-app alternative payment processing will pay 20%.

[…]

Apps that link to a website purchase option will pay 15%.

Apps using Web Distribution or App Marketplaces would pay the 5% CTC (and report transactions). I like that the new terms are simpler and that the fees are slightly lower, but it seems like the EU got tricked or surrendered here.

EMIRELADERO:

This is bonkers, I can’t believe the EU Commission agreed to it. The main issue that the DMA was about still remains: Apple retains ultimate control over app developers’ dealings with users.

The status quo that the EU should have pushed for, and which Article 6(7) of the DMA requires, is one where a developer can distribute iOS apps to users without ever entering into any contractual relationship with Apple.

mjorgers:

All in all, still extremely anti-consumer. If I can download and run arbitrary code on my Mac--even if I have to jump through scary warnings--why should I not be able to do so on my phone? Why would one computing platform be different from the other?

Ben Lovejoy:

However, while Apple hopes it will be allowed to charge these lower commissions, it has admitted in a new regulatory filing that it may not be allowed to charge any commission at all on purchases made through third-party app stores and other external platforms.

Tim Hardwick:

The commission Apple earns from the App Store is shrinking in markets where it has been forced to relax its grip on in-app purchases, based on new analytics data.

Previously:

Update (2026-08-20): M.G. Siegler:

Notably, this isn’t a proposal, it’s the announcement of actual changes that Apple will implement (starting October 1) after “close collaboration” with the EC. And lest we think Apple is overplaying that last aspect, that group gave a statement to Bloomberg backing up the assertion[…]

[…]

This feels like mainly a way to keep the all-important big gaming fees – which make up most of in-app payments, and as such, most App Store fees – mostly intact.

[…]

It sure looks like Apple knew this EU deal was coming down the pike and that the bloc agreeing to their terms would bolster the case that these are “fair”. The US judge still gets to decide that, and Epic has already pushed back as Apple seeks to negotiate directly. One big reason for pushing? Epic wants to ensure any changes Apple tries to negotiate be put in place for all developers.

Juli Clover:

The European Commission has since confirmed that it approves of Apple’s changes to its App Store policies, giving a statement to the Irish Independent[…]

Richard Speed:

Epic Games, a longstanding critic of Apple’s App Store practices, called the scheme “junk fees,” adding that the plan did “nothing to open up the mobile app ecosystem to competition, as required by Digital Markets Act.”

“The law makes it clear that Apple must allow developers to offer link outs to the web for purchases ‘free of charge’ and has to allow ‘effective use’ of competing stores,” the company wrote.

Rui Carmo:

This changes effectively nothing I care about and continues to be completely laughable.

Kyle Howells:

Apple still in complete control over what is allowed in any iOS app.

Fabian Pimminger:

It’s so weird to me that the regulation that is explicitly against gatekeepers still allows Apple to be the gatekeeper.

Thomas Clement:

I hope this isn’t the end of DMA. Apple taking a cut of out-of-store apps revenue makes as much sense as app developers taking a cut of iPhone revenue.

[…]

And also I still want to live in a world where anyone can write a program and run it on the devices they own and send it to friends, without having to pay $100/year of developer account and do the whole notarization thing (which considering the amount of scam in the app store we know is pretty useless in terms of security). Not everybody is a professional programmer, some people are just doing programming as a hobby, some are also young people that don’t even own a credit card yet.

Steve Troughton-Smith:

I have refused to sign any of Apple’s EU DMA agreements thus far, because I think they are illegal, and they have been optional.

I still think their new terms are illegal — they don’t meet the minimum requirements of the DMA, and will not be approved by stakeholders — but they are no longer optional, so the choice now becomes accept the updated developer agreement or stop being a developer.

Update (2026-08-21): John Gruber:

This is a near-total victory for Apple.

[…]

Thanks to the DMA’s sprawling scope, complexity, and overreach, Apple came out of this conceding only 4 percent of the App Store’s 30 percent commission, and no reduction at all to the 15 percent for subscriptions after the first year.

Update (2026-08-24): Jesper:

The CTC is preferable to the CTF in much the same way that a fire burning down your kitchen is preferable to a fire burning down your entire house.

[…]

The Digital Markets Act was introduced to ensure that sideloading would be an available alternative, to essentially force open platforms that have been closed. Debates about the wisdom of this notwithstanding, in the biggest case, and up until recent developments in Android app marketplace governance also only case, it has failed to deliver the promises that were the entire point of the law.

Update (2026-08-25): John Gruber (Mastodon):

I’m sure some of you think I’m all wet in my argument that the point of the DMA was merely to impose ongoing bureaucratic complexity. But my view jibes with the reality of how it’s worked out.

In other words, maybe we who had high hopes were the ones who got tricked, not the EU Commission.

Update (2026-08-28): John Gruber:

I don’t recall seeing POSIWID before, but I love the concept. A friend sent this to me, with the quip that I forgot to include a link to it in my “What Is the Point of the DMA?” piece this week. Indeed, it encapsulates my arguments about the DMA specifically and the European Commission generally. The purpose of the DMA is what it does, not what you imagine it is intended to do.

I admit to being primed by seeing Jeff Johnson’s post, but I’m certain that my mind would anyway have immediately gone to our favorite scam promoting toll booth, the place that “gives people around the world a safe and trusted place to discover apps that meet [Apple’s] high standards for privacy, security, and content.”

Also consider which apps have to pay the toll and which ones show their own ads for free.

macOS 26.6.2

Joe Rossignol (release notes, security, no enterprise, no developer, full installer, IPSW):

macOS 26.6.2 delivers security fixes that were first made available in the macOS Golden Gate 27 beta.

Howard Oakley:

There don’t appear to any matching security updates to Sequoia or Sonoma, though.

See also: Mr. Macintosh.

Previously:

iOS 26.6.1 and iPadOS 26.6.1

Joe Rossignol (iOS/iPadOS release notes, security, no enterprise, no developer):

Apple today released iOS 26.6.1, iPadOS 26.6.1, visionOS 26.6.1, and macOS 26.6.2, with all of the updates containing security fixes.

Apple also released iOS 18.7.10 and iPadOS 18.7.10 with security fixes.

The version numbers are now out of sync with macOS because macOS 26.6.1 fixed an important screen sharing vulnerability a few weeks ago.

Juli Clover:

There are fixes for an audio vulnerability that could allow an app to leak sensitive user information, an image vulnerability that could allow for arbitrary code execution, a trio of kernel vulnerabilities, and several WebKit bugs that could cause memory corruption or Safari crashes. Of the 29 CVEs outlined in the document, 21 are WebKit-related, and nine are credited to OpenAI Codex Security.

On iOS, Apple also fixed a telephony bug that could allow an attacker in a privileged network position to bypass IPSec authentication and intercept network traffic.

Previously: