Top
Best
New

Posted by _-x-_ 11 hours ago

Tell HN: An app is silently installing itself on my iPhone every day

Every day for the past 3 days around 1pm EST the 'Headspace' app has been silently appearing on my iPhone (13 Pro). Automatic downloads are turned off and I've updated to the latest iOS since this started happening.

I googled around and found a couple reddit threads with people reporting the exact same thing starting 2 or 3 days ago. There were reports from people on iPhone 12 and iPhone 17 so it doesn't seem device-specific.

Anyone else seeing this? Does anyone understand how or why this is happening?

322 points | 124 comments
usef- 6 hours ago|
This isn't the first system bug that primarily was visible due to headspace: https://www.macrumors.com/2017/12/02/ios-11-1-2-date-bug-cra...

In 2017 it was an endless crash loop caused by any app with local time-based notifications.... Which for almost everyone at the Apple store I visited was meditation apps with daily meditation reminders (in Australia we were among the first to wake up on that affected date. The fix went out before most of the remaining world woke up)

I wonder if the daily reminder is triggering a reinstall? Perhaps try disabling the reminders before uninstalling.

_-x-_ 9 hours ago||
Here's a Reddit thread of other people experiencing the same issue: https://www.reddit.com/r/ios/comments/1su82sc/headspace_app_...
cortesoft 7 hours ago||
This is fascinating. I am very curious to find out what the actual cause of this turns out to be.
dyauspitr 3 hours ago|||
It downloaded itself on my phone as well. I thought it was some quirk with the Apple Watch sync because I used to have headspace installed at some point and that automatically shows up on the Apple Watch but deleting an app on the iPhone doesn’t always delete the corresponding Apple Watch app. So if you open headspace on the Apple Watch I assumed it redownloaded itself on the iPhone.
trueno 7 hours ago|||
same. i get blasted with ads for this app on whatever platform, never installed it myself. the amount of promotions + this = my underdeveloped brain is so ready to assume the worst here. been a while since i used my pitchfork & i'm here for the riot.

if it is, in fact, something nefarious at play that would be a pretty crazy 2026 era exploit. but i'm certain it's a bug/artifact of some sort that, for whatever reason, affects this specific app.

powersnail 6 hours ago||
Maybe the developer was using Headspace as part of the test data and it bled into production?

It's hard to imagine what Headspace would like to achieve if this were an exploit executed by them. It's so salient, that it makes no sense to do on purpose. At least some portion of Apple employees and their families are going to be affected by this, and this would escalate to the legal department immediately.

My money is on Apple being the buggy one here.

trueno 6 hours ago|||
> My money is on Apple being the buggy one here.

Yeah I'm thinking some sort of test artifact bleeding into prod and subject so some nightly process is likely the case.

red_admiral 4 hours ago||||
I feel sorry for the headspace devs if it's really 100% Apple's fault.
concinds 4 hours ago|||
I wish Apple released incident reports in cases like these. I hate that their secrecy obsession extends so far beyond hardware.
Bjartr 9 hours ago|||
Based on that I'd guess either a meditation app company has figured out how to circumvent a lot of controls put in place by Apple, or it's a bug on Apple's side
_-x-_ 9 hours ago|||
Yeah, I think the latter is more likely than the former. Perhaps a server side bug that's silently downloading the app on any device that's installed it previously?
donkey_brains 8 hours ago||
But why this one specific app and no others?
layer8 7 hours ago|||
Maybe it’s Apple’s equivalent of Guru Meditation.
altairprime 6 hours ago||||
Maybe Apple typo’d an app id incorrectly for some iOS core app thing in 26.4.2 and the one-character error is this app? I don’t know that anyone’s done a ‘likelihood of collision’ analysis on appstore unique IDs yet. Certainly I could see iOS having a “must be on the device” system set up for apps like Phone and Settings that has a last-ditch of reinstalling it if somehow deleted. Would be especially interesting if some core app that can’t normally be deleted is currently unprotected (back up your device locally first!).
_-x-_ 8 hours ago||||
Right, that's what confuses me the most. I was very surprised to find the reddit thread showing that other people are also having this specific app silently installed on their devices.
breppp 7 hours ago|||
Headspace leaves health data, that's where my first guess would be
joenot443 1 hour ago||||
My guess is it's a bug on the App Store side which will actually hurt Headspace in the long run. If this was a casino app I'd feel a bit differently, but I'd be shocked if someone at Headspace did this deliberately.

I'm trying to imagine the headspace of a user who deletes an app, only to see it pop back the next morning. Probably not a very relaxing experience :)

a34729t 8 hours ago||||
Or it is a mandated backdoor, and someone internally objected, and made it easier to exploit than it should be, or leaked how to exploit it?
8cvor6j844qw_d6 8 hours ago||
> mandated backdoor

Probably one from the repository of backdoors "accidentally" introduced or "never" discovered.

The mechanism's there, just needs to be woven with other exploits.

aaron695 7 hours ago|||
[dead]
bharat1010 5 hours ago||
looks like, no where its safea anymore
visiondude 5 hours ago||
My hypothesis is that headspace registered many user notifications and since user notifications trigger an app launch and perhaps you have optimize storage by offloading apps enabled? ios has a quirky app state where some local data exists but the app itself (ipa package) is offloaded
aaronbrethorst 7 hours ago||
I wonder if U2, or Bono, has taken a significant stake in Headspace recently (kidding).
fmajid 3 hours ago||
It's not good four my blood pressure to be reminded of that sanctimonious tax-dodging hypocrite.
andy_ppp 48 minutes ago||
Have you considered meditation? ;-)
steve1977 5 hours ago|||
A 50th anniversary gift you mean?
edbaskerville 6 hours ago|||
Deep cut
swiftcoder 5 hours ago||
Jesus, I hope not. That happened just a few years ago... right?
stingraycharles 4 hours ago|||
Wasn’t that around the release of the iPhone X?
dtech 3 hours ago|||
More than a decade ago
meindnoch 4 hours ago||
It was so fucking funny. I wonder what the engineer thought, who had to issue the SQL query which added Bono to literally everyone's collection. Like, I'm not surprised that management was so out of touch, but I'd expect the engineers to have a bit of common sense...
PunchyHamster 3 hours ago|||
What he was going to do, ignore management ? There is always someone else clueless or not caring enough to do it
mort96 2 hours ago||||
I feel like that's the kind of thing it's easy to not recognise as a terrible idea until after it's done, because so much of what makes it a bad idea is a consequence of the rest of the system.

Imagine if everything else surrounding the Apple ecosystem worked better. Imagine if people who don't actively use Apple Music never experienced Apple Music starting to play music by itself. Imagine if people who do use Apple Music never had an album play without being actively interacted with. Imagine if the album cover wasn't low-key softcore gay porn. Imagine if you could "uninstall" an album you own, like how you can uninstall an app you own and never ever see it again unless you actively go out of your way to search for it on the App Store.

Would it still have been a violation of consent? Sure, yeah it would. But almost everything people complain about is related to how it starts to play when they don't want to (an issue with iOS/macOS and Apple Music that would be annoying regardless), or how the album cover sometimes unintentionally pops up on your screen (such as when you hit the play/pause button on Mac when macOS doesn't think that there's any active paused media, so macOS opens Apple Music), or how there is no way for them to get rid of the album once they own it. These things are pretty large problems regardless of Songs of Innocence.

I can sort of understand an engineer thinking that surely there can't be any major downsides to just giving away a digital good. And if the rest of iOS, macOS's, Apple Music and the album itself didn't have all these issues, it wouldn't have been much of an issue. Again, it would've been a consent violation, but developers at tech companies aren't exactly known for valuing consent anyway and everyone would've certainly forgot it by now.

nottorp 1 hour ago||
> Imagine if people who don't actively use Apple Music never experienced Apple Music starting to play music by itself.

Nice dream. My wireless headphones act like in the manual when paired with my phone, but the buttons on them always start apple music when paired with my laptop instead of muting or controlling noise canceling.

kotaKat 33 minutes ago||||
"We wanted to deliver a pint of milk to people's front porches, but in a few cases it ended up in their fridge, on their cereal. People were like, 'I'm dairy-free.'" -Bono

Literally imagining the milk man bursting in to dump a gallon of milk on some poor sod's cereal this morning.

baq 3 hours ago||||
And do what? Quit and have someone else execute the query for something that’s in the grand scheme of things irrelevant?
actionfromafar 4 hours ago|||
They follow orders, like soldiers do.
COFyumo 8 hours ago||
I have the same exact thing happening. I deleted the app a few days ago when was surprised to see it in my app list.

I had previously downloaded the app but and removed it because I never used it. A few days ago I noticed the app when browsing through my app list and thought maybe I didnt delete it properly, so I made sure to delete it. Then this morning my iPhone updated software versions and I found he Headpsace app again on my home, except this time it was grayed out and waiting for me to go on wifi to download.

I just deleted it again but am equally dumbfounded

_-x-_ 7 hours ago|
That's interesting that it still showed up on your homescreen despite not being able to download
yokuze 8 hours ago||
Do you have Settings > Apps > App Store > (Automatic Downloads) App Downloads turned on?

I noticed apps appearing on my Home Screen I’d never heard of before. Turns out with that setting and Family Purchase sharing turned on, every time my wife installed a new app, it installed on my phone too.

That may not be your exact scenario, but I wonder if turning off that Automatic App Downloads setting (if enabled) changes anything. Could give you a clue, if so.

_-x-_ 8 hours ago|
App Downloads and App Updates are both turned off. I don't have anyone else's devices on my account, just me. Thank you for the suggestions though!
wallst07 1 hour ago|||
Even with auto downloads turned off, does it show up in your app library or as a purchased app?

You can still have a app library with apps that "should be" downloaded, what happens if its removed from that list?

saagarjha 2 hours ago||
If you can take a sysdiagnose I’m sure it will have the answer in it. If you want to send me one (note: may contain sensitive information) feel free to contact me or any other person you trust who is familiar with iOS stuff?
doncho 6 hours ago||
Very interesting, especially if it found a way to bypass the explicit disabling of automatic downloads…

Now imagine you’re roaming during a 10-day vacation…and you think you’re in control :) …

nottorp 6 hours ago||
Meanwhile, I can't install an iOS game i bought in 2021 (Azure Saga if it matters) because it's delisted from the app store.

Damned if you pay them, damned if you don't.

forsalebypwner 5 hours ago|
Took me a minute but I found it https://archive.org/download/iklassika_archive/AzureSagaPath...
nottorp 5 hours ago||
Probably requires a jailbroken ipad?

I'll take it as a lesson to not even look at games on iOS [1]. I added it to my wish list on Steam, i might get it on a sale.

[1] Not that iOS has many games. I can't afford the free ones.

forsalebypwner 3 hours ago||
No jailbreak required, just sideload it with a tool like Sideloadly. There are plenty of games, but it's understandable if you don't want to support Apple's practices.
janstice 10 hours ago|
Is your phone connected to some work mobile device management? I could imagine someone has a jinxed Jamf or intune rule that is pushing things out.
_-x-_ 10 hours ago|
No, this is my personal device. It has never been connected to any MDM.
Schiendelman 9 hours ago||
Have you actually checked your device management settings?
_-x-_ 9 hours ago|||
Yes. In Settings > General > VPN & Device Management, it says 'Sign in to Work or School Account'. Is there a different device management setting that I should be looking at?
Schiendelman 8 hours ago||
That's the one. I was worried you might have something you didn't know about!
teruakohatu 9 hours ago|||
Yes, there are alt app stores that try to get you to agree to installing a MDM
More comments...