September 28 2026
My blog post yesterday, App Store review allowed a Meta Muse copycat, highlighted not just one but three obvious scams currently in the App Store. Reactions such as this Reddit comment are frustrating but common:
Considering the thousands of apps submitted daily and the queue management the App Store maintains, it’s easy for some apps to fall through the cracks. To call it abitrary [sic] and that it “doesn’t even work” is a bad and reductionist take based on outliers.
I understand the frustration as a developer, but compared to other options, pretty much just the Google play store, it’s night and day
The same commenter later adds:
You literally have no idea how many apps are caught before they reach the App Store and how much manual review and touches are involved. You are seeing the tip of the iceberg from a limited, outsider perspective.
Not saying that some misses are clearly misses, as you pointed out with your example, but you are ignoring hundreds to thousands of apps per day/week that are being reviewed and rejected before they see the light of day. I’m not saying this to defend Apple, but the assembly line of app review is so much more elaborate than you’re acknowledging and is a tighter system than any other App Store, period.
My intention here is not to respond to that specific commenter, one anonymous person. However, I think that the commenter is representative of a large number of defenders of the App Store, so it’s useful to look at these specific comments in that way, as representative of a common view. In short, the view is that Apple review of App Store apps is competent and helpful albeit imperfect. In contrast, my view is that Apple review of App Store apps is utterly incompetent and unhelpful. The title of this blog post reflects these contrasting views.
I’ve been documenting App Store scams for many years on my blog and on social media. In addition to the scams I highlighted yesterday, countless others can be seen by following the links in My collected App Store critiques. The Reddit commenter claims that the scams receiving public attention are “the tip of the iceberg from a limited, outsider perspective,” which is an accurate metaphor, yet the commenter and I have dramatically different interpretations of that metaphor. For the commenter, the iceberg represents the vast number of scams allegedly caught by Apple app review but not seen by the public; for me, the iceberg represents the vast number of scams not caught by Apple app review and not seen by the public either. To put the argument another way, the commenter appears to assume that the majority of scams in the App Store receive widespread public attention, in blog posts such as mine or in the news media, so the relatively small number of stories we hear is indicative of a relatively small number of scams in the App Store, whereas my own impression is that the vast majority of scams in the App Store do not receive widespread public attention. Scam hunting is not my job, merely an occasional hobby. It’s so easy for me to find scams, they practically fall into my lap whenever I look. I could spend all day every day finding and listing App Store scams, if I were sufficiently motivated (I’m not). You would think that someone working for Apple would be sufficiently motivated, by a paycheck, to spend all day every day finding and listing and most importantly removing App Store scams, but I’ve seen no evidence of it. Apple employees should make my hobby fruitless, no? In any case, even when I do find scams, I often have trouble publicizing them, because “scams in the App Store” is old news that people have read before. Ironically, the more scams I and others find, the less people notice them, boredom by repetition.
It’s curious how the Reddit commenter vacillates between knowledge and ignorance of the App Store review process. On the one hand, the commenter claims that publicized scams are “outliers.” On the other hand, the commenter claims, “You literally have no idea how many apps are caught before they reach the App Store.” The latter claim is demonstrably untrue, because Apple actually publicizes these numbers. For instance, according to the 2025 App Store Transparency Report, there were 2,172,472 apps in the App Store, 166,899 apps removed from the App Store, 9,100,620 app submissions reviewed, and 2,093,244 app submissions rejected, though the majority of rejected submissions appeared to be non-malicious, indeed 387,087 submissions were approved after initial rejection. (Note: a submission is a specific version of an app. Every app update is reviewed by Apple.) Of the 166,899 apps removed (“Apps may be removed from the App Store for a number of reasons, including violations of local law, repeated violations of App Store policy, fraud, and demands by regulators”), 90,608 were for fraud, 418 for spam, and 279 for copycats. The Apple press release The App Store stopped over $2.2 billion in potentially fraudulent transactions in 2025 reaffirms some of those numbers—“9.1 million+ App Store submissions reviewed,” “2 million+ app submissions rejected for failing to meet Apple’s standards”—and provides some additional context: “371,000+ app submissions identified as spam, copycats, or misleading,” around 4% of all submissions and 18% of all rejections.
I consider some of Apple’s numbers shockingly low, especially the 279 copycats removed, given my blog post yesterday about copycats. I don’t think the numbers reveal the internal iceberg posited by the Reddit commenter. The published numbers suggest that App Store review is mostly hassling non-criminal developers. By the way, one Apple statement left me puzzled:
To further protect the integrity of app discovery, Apple blocked nearly 7,800 deceptive apps from appearing in App Store search results and an additional 11,500 apps from appearing on App Store charts, ensuring that honest developers are properly showcased for their innovation and hard work.
My question is, did Apple remove these apps from the App Store? Of course an app removed from the App Store would in a sense be “blocked” from appearing in App Store search results and charts, but that’s an odd way of wording it. The alternative interpretation is that Apple only blocked deceptive apps from appearing in the search results and charts but nonetheless left the deceptive apps in the App Store? Needless to say, my blog post yesterday demonstrated that there’s much more work to be done in this area.
For the purposes of this blog post, I would distinguish between malware and scams. Malware, as I’m defining it here, is secretive and involves software engineering. Scams are overt and involve social engineering. According to this distinction, the apps mentioned in my blog post yesterday are scams but not malware. As far as I know, those apps do not harm your devices or steal your data. Nonetheless, they can steal your money by tricking you into expensive subscriptions. For many people, losing money can be as harmful as or more harmful than malware, so I think we should treat scams with equal seriousness to malware. I’m not aware of much malware on the App Store, but I don’t think this is a testament to Apple app review. By design, iOS is an extremely restrictive operating system. If you think that app review is catching malware, I challenge you to download Apple’s Xcode developer tools, write a malware app—you can vibe-code it if you like—and run the malware app on your own device or in the iOS simulator, bypassing app review. Go ahead, I’ll wait! This is not to say that iOS malware is impossible to produce, but it’s difficult.
App reviewers are not software engineers and can’t reverse-engineer app binaries. They’re totally unqualified to find malware. Here’s a quote from the 2021 news story Apple’s tightly controlled App Store is teeming with scams:
In a sworn deposition in the Epic lawsuit, Phillip Shoemaker, the former head of the App Review team, said employees in his department generally did not have a technical background in computer coding. They needed to know how to use a Mac and an iPhone, he said.
“Qualifications were that they could breathe, they could think,” he said. And they typically worked at the Apple “Genius Bar” at the company’s retail stores. It typically took about 13 minutes to review a new app, Shoemaker said in the deposition.
They could breathe, could think, so at least Apple rejected the zombie applicants! It appears that the workload for app reviewers has increased since Shoemaker left, though. According to the Apple App Store page, “Every week, nearly 500 dedicated experts around the world review over 130K apps.” This may be a 2024 stat, because it amounts to 6.8 million submissions rather than the 9.1 million in 2025 mentioned before, and there are two other references to 2024 on the page. If 500 employees worked 40 hours a week reviewing 130k app submissions with no breaks, vacations, or meetings, that would leave an average of 9 minutes to review everything about the submission, including app functionality, In-App Purchases, and App Store metadata. We don’t know whether the number of app reviewers has increased since 2024, but we do know the number of app submissions has increased significantly (possibly due to LLM assistance). Good luck catching hidden malware. The funny thing is that some people say of the Epic vs. Apple dispute that “Fortnite was literal malware” for adding secret code to allow Fortnite users to purchase V-Bucks directly from Epic, bypassing the Apple IAP system. But the Fortnite update with this secret code was approved by Apple app review! They did not detect the so-called “malware” until it was already in the App Store and in the hands of users.
Apple does have some automated systems for detecting malware in App Store submissions. As far as I’m aware, Apple has not published statistics about the effectiveness of these systems. Regardless of the effectiveness, or ineffectiveness, Apple also requires Mac developers to submit their apps for a malware scan in order to be notarized for distribution outside the Mac App Store. Thus, malware is not a good excuse to impose human review on apps.
Although macOS is not nearly as restrictive an operating system as iOS, the Mac App Store does impose a technical requirement on app submissions, sandboxing, that strictly limits the capabilities of a Mac app. The Mac app sandbox is not as restrictive as the built-in iOS app sandbox, but it’s still quite restrictive and effective. Thus, the scarcity of malware in the iOS and Mac App Store should be credited to Apple engineering rather than to Apple app review. I wouldn’t expect app reviewers to catch hidden malware. If app reviewers can’t catch obvious scams, however, then what good are they?
Nobody knows the true failure rate of Apple app review, not even Apple. That would require knowing the true number of scams allowed in the App Store, and if Apple knew that, wouldn’t Apple remove those scams and make the number zero, rather than allowing scams to persist, sometimes for years? If you want to estimate the failure rate, it’s crucial to consider not just the quantity but also the quality of the failures. What does it say about the failure rate of app review that they keep missing the most obvious, blatant scams, the ones that practically scream scam at first glance? Does that somehow give you the confidence that their failure rate is low? The “few bad apples” argument is a double-edged sword, because it cites the volume of apps in the App Store—the scams are allegedly only a small percentage out of millions—but when it comes to app review, the volume of apps is a liability! They have to review over 9 million submissions per year now, and can spend mere minutes on each submission. At the same time you’re estimating the failure rate of app reviewers, you should estimate the amount of time they spend on a review. Is it so implausible that app review would frequently mess up when they’re hopelessly overworked? Five hundred against the world are not favorable odds; I bet on the world to beat app review.
In my first-hand experience as a longtime App Store developer, and second-hand experience as an active member of the Apple developer community, I’ve come to feel that “they could breathe, they could think” are actually maximum rather than minimum requirements for App Store reviewers. They seem so clueless. Even the “know how to use a Mac and an iPhone” qualification is questionable. And app reviewers certainly don’t know the App Store market, which is odd, since they see so much of it. I can’t help but suspect that app reviewer is a relatively low-paying, high-turnover job, belying Apple’s characterization of reviewers as “dedicated experts.” Of course “Apple Genius” was itself always an exaggeration. I enjoy my job as an app developer, but if I had to choose between Apple Genius and Apple app reviewer, I’d work at the Genius Bar, no question. App review seems like a tedious, unrewarding, mindless assembly-line type of job. (Our Reddit commenter called it “the assembly line of app review,” an inadvertent criticism in what I think was intended to be praise for efficiency.) How many “bug fixes and performance improvements” updates could I see every day before going insane? Maybe I’d approve scams just to spice things up a little, an office prank. Anyway, how much money could Apple be investing in app review when its services revenue margin is 75%?
If App Store reviewers fall for scams as easily as App Store users, then app review is superfluous.