Apple removes Trend Micro tools from Mac App Store over “data exfiltration” claims

Trend flatly denies experts’ claims it is stealing user data and sending it to China

Trend Micro website displayed on a smartphone device

A host of anti-malware tools developed by cyber security company Trend Micro have been removed from Apple's Mac App Store.

Six apps including Dr. Cleaner and Dr. Antivirus have disappeared from the Mac App Store after experts, including Malwarebytes Labs' head of Mac Thomas Reed, spotted that user data was needlessly being 'exfiltrated' from these products.

Examining the apps' code, Reed and others also claimed Trend Micro's repertoire of apps was sending data to a server in China based on the fact a domain was registered in the country - a charge Trend Micro flatly denies.

"It's blindingly obvious at this point that the Mac App Store is not the safe haven of reputable software that Apple wants it to be," Reed said.

Advertisement
Advertisement - Article continues below

"I've been saying this for several years now, as we've been detecting junk software in the App Store for almost as long as I've been at Malwarebytes. This is not new information, but these issues reveal a depth to the problem that most people are unaware of."

Apple, having revamped its rules earlier this year to prioritise user privacy, began removing Trend Micro's apps once alerted to the complaints two days ago - with all apps now off the store at the time of writing.

Facebook just last month clashed with Apple over data collection concerns surrounding its controversial Onavo Protect VPN app; voluntarily removing its service from the App Store after talks with the iPhone manufacturer.

Trend Micro denied all claims it was stealing user data and sending them to an unidentified server in China, branding them "absolutely false".

In a post responding to the controversy, the Japanese firm said it completed an investigation into the six apps removed from the Apple Mac Store and concluded they "collected and uploaded a small snapshot of the browser history on a one-time basis".

In a further update, Trend Micro confirmed it had removed the data collection features across the consumer products in question, and permanently dumped legacy logs stored on a US-based AWS server.

Finally, the company identified what it claimed to be a "core issue which is humbly the result of common code libraries", learning the data collection functionality was designed the same across all of its apps regardless of whether this was necessary for the app to work.

"The potential collection and use of browser history data was explicitly disclosed in the applicable EULAs and data collection disclosures accepted by users for each product at installation," the company said.

"The browser history data was uploaded to a U.S.-based server hosted by AWS and managed/controlled by Trend Micro.

"We apologise to our community for concern they might have felt and can reassure all that their data is safe and at no point was compromised."

Advertisement
Advertisement - Article continues below

IT Pro has approached Apple for comment but it had not responded at the time of publication. 

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/strategy/28185/what-is-data-mining
Business strategy

What is data and big data mining? An easy guide

22 Aug 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/security/identity-and-access-management-iam/354289/44-million-microsoft-customers-found-using
identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019
Visit/mobile/5g/354286/why-5g-could-be-a-cyber-security-nightmare
5G

Why 5G could be a cyber security nightmare

6 Dec 2019