In brief
Check affected apps for updates and install any available update to resolve the problem. In its notice, Apple said it was removing infected apps and blocking new ones, with no indication at the time of malicious incidents or transmission of personally identifiable information.
Several days have passed since the Xcodeghost malware incident involving apps on the App Store. Today, Apple finally issued an official notice responding to the incident and explaining how users should respond.
What happened?
Apple first explained that the incident arose because developers downloaded pirated copies of the Xcode development tools that had been infected with malware. The apps built using those tools were also infected. Developers downloaded these pirated copies of Xcode from sources other than Apple's official channels to speed up their downloads.
How does this affect users?
Apple stated that there was currently no indication that the infected apps had caused any “malicious incidents”, nor was there any indication that these apps had been used to transmit any personally identifiable information. The malware also could not obtain passwords for iCloud or other services through users' identities.
What should users do?
Apple said that it would remove infected apps as soon as they were discovered. It had also blocked new infected apps from entering the App Store. If you have already installed any of the infected apps, check whether updates are available. If an update is available, installing it will resolve the problem. Previously affected apps that return to the App Store have been updated to remove the malware; any app that has not yet returned will be updated soon.
https://hk.lifestyle.yahoo.com/apple-%E7%B7%8A%E6%80%A5%E9%80%9A%E5%91%8A-%E5%85%AC%E9%96%8B%E6%9C%89%E6%AF%92-ios-apps-060949737.html