USENIX Security2026Top-tier venue
Cracks in the Walled Garden: Dissecting the Gray-Market of Unauthorized iOS App Distribution via Ad Hoc Sideloading
Yijing Liu, Yiming Zhang, Baojun Liu, Haixin Duan
Abstract
Apple enforces strict code signing and mandates app distribution through its official App Store. Nonetheless, unauthorized apps still spread through sideloading channels. The Ad Hoc provisioning mechanism, originally designed for developer testing, has emerged as one such channel. It leverages individual developer certificates and user-side signing to enable unauthorized app installations that bypass Apple's app review process. Over time, this practice has evolved into a structured and prevalent gray-market that connects certificate resale, third-party signing tools, and the distribution of unsigned .ipa files. In this work, we present the first systematic study of this market, with a specific focus on its integrated service operations in China. Through a user-centric data collection strategy, we identified 3,359 active signing sites for certificate redemption, reverse engineered 12 signing tools, and obtained 8,216 distributed .ipa entries. Our analyses uncover a multi-layered certificate circulation model with resale margins up to 3,000% and reveal common tricks that signing tools employ for code signing. Most distributed apps are modified versions of legitimate ones, which leverage dynamic library injection to enable customized features. Such modifications undermine the security protections that both apps and the system provide to users, exposing them to risks such as unauthorized actions, sensitive data exfiltration, and system capability exploitation. Overall, our findings reveal a mature gray-market that erodes iOS's trust model while operating in plain sight, underscoring the need for targeted interventions from multiple stakeholders.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5d6193ca-ebbd-4664-8e90-1d2422008018Builds on6
- "Desperate Times Call for Desperate Measures": User Concerns with Mobile Loan Apps in KenyaCollins W. Munyendo, Yasemin Acar, Adam J. AvivS&P 2022 · 32 citations
- VAHunt: Warding Off New Repackaged Android Malware in App-Virtualization's ClothingLuman Shi, Jiang Ming, Jianming Fu, Guojun Peng et al.CCS 2020 · 24 citations
- Tickets or Privacy? Understand the Ecosystem of Chinese Ticket Grabbing AppsYijing Liu, Yiming Zhang, Baojun Liu, Haixin Duan et al.USENIX Security 2024 · 4 citations
- Characterizing the MrDeepFakes Sexual Deepfake MarketplaceCatherine Han, Anne Li, Deepak Kumar, Zakir DurumericUSENIX Security 2025
- Analyzing the iOS Local Network Permission from a Technical and User PerspectiveDavid Schmidt, Alexander Ponticello, Magdalena Steinböck, Katharina Krombholz et al.S&P 2025
Related papers
- SandScout: Automatic Detection of Flaws in iOS Sandbox ProfilesLuke Deshotels, Razvan Deaconescu, Mihai Chiroiu, Lucas Davi et al.CCS 2016 · 20 citations
- Demystifying Illegal Mobile Gambling AppsYuhao Gao, Haoyu Wang, Li Li, Xiapu Luo et al.WWW 2021 · 30 citations
- iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOSDexin Liu, Yue Xiao, Chaoqi Zhang, Kaitao Xie et al.USENIX Security 2024 · 6 citations
- OS-level Side Channels without Procfs: Exploring Cross-App Information Leakage on iOSXiaokuan Zhang, Xueqiang Wang, Xiaolong Bai, Yinqian Zhang et al.NDSS 2018 · 34 citations
- CHAMELEOSCAN: Demystifying and Detecting iOS Chameleon Apps via LLM-Powered UI ExplorationHongyu Lin, Yicheng Hu, Haitao Xu, Yanchen Lu et al.NDSS 2026 · 1 citation
