Archive for August 18, 2026

Tuesday, August 18, 2026

New EU App Store Terms to Comply With DMA

Apple (developer, details, Hacker News, TechCrunch, The Verge, 9To5Mac):

These changes resolve Apple’s disagreements with the Commission over business terms and alternative distribution. They also reduce complexity by moving every developer that distributes apps in the EU to a single set of business terms.

[…]

The Core Technology Fee, a per-install fee for developers that achieve extraordinary scale, will be replaced by the Core Technology Commission, a simple 5 percent commission on digital transactions in apps distributed outside the App Store. The new terms also eliminate the initial acquisition fee and store services fee.

[…]

Under the updated terms, developers can now offer Apple In-App Purchase alongside alternative payment options, which had not previously been permitted in the EU.

[…]

Apple is also expanding who is eligible to operate an alternative app marketplace or distribute apps via the web in the EU.

[…]

Apple will continue to require every alternatively distributed app to go through Notarization[…]

Juli Clover:

Apple will charge a 26% fee for apps distributed through the App Store that use in-app purchase.

[…]

Apps in the App Store that use in-app alternative payment processing will pay 20%.

[…]

Apps that link to a website purchase option will pay 15%.

Apps using Web Distribution or App Marketplaces would pay the 5% CTC (and report transactions). I like that the new terms are simpler and that the fees are slightly lower, but it seems like the EU got tricked or surrendered here.

EMIRELADERO:

This is bonkers, I can’t believe the EU Commission agreed to it. The main issue that the DMA was about still remains: Apple retains ultimate control over app developers’ dealings with users.

The status quo that the EU should have pushed for, and which Article 6(7) of the DMA requires, is one where a developer can distribute iOS apps to users without ever entering into any contractual relationship with Apple.

mjorgers:

All in all, still extremely anti-consumer. If I can download and run arbitrary code on my Mac--even if I have to jump through scary warnings--why should I not be able to do so on my phone? Why would one computing platform be different from the other?

Ben Lovejoy:

However, while Apple hopes it will be allowed to charge these lower commissions, it has admitted in a new regulatory filing that it may not be allowed to charge any commission at all on purchases made through third-party app stores and other external platforms.

Tim Hardwick:

The commission Apple earns from the App Store is shrinking in markets where it has been forced to relax its grip on in-app purchases, based on new analytics data.

Previously:

macOS 26.6.2

Joe Rossignol (release notes, security, no enterprise, no developer, full installer, IPSW):

macOS 26.6.2 delivers security fixes that were first made available in the macOS Golden Gate 27 beta.

Howard Oakley:

There don’t appear to any matching security updates to Sequoia or Sonoma, though.

See also: Mr. Macintosh.

Previously:

iOS 26.6.1 and iPadOS 26.6.1

Joe Rossignol (iOS/iPadOS release notes, security, no enterprise, no developer):

Apple today released iOS 26.6.1, iPadOS 26.6.1, visionOS 26.6.1, and macOS 26.6.2, with all of the updates containing security fixes.

Apple also released iOS 18.7.10 and iPadOS 18.7.10 with security fixes.

The version numbers are now out of sync with macOS because macOS 26.6.1 fixed an important screen sharing vulnerability a few weeks ago.

Juli Clover:

There are fixes for an audio vulnerability that could allow an app to leak sensitive user information, an image vulnerability that could allow for arbitrary code execution, a trio of kernel vulnerabilities, and several WebKit bugs that could cause memory corruption or Safari crashes. Of the 29 CVEs outlined in the document, 21 are WebKit-related, and nine are credited to OpenAI Codex Security.

On iOS, Apple also fixed a telephony bug that could allow an attacker in a privileged network position to bypass IPSec authentication and intercept network traffic.

Previously: