NewsLab
Apr 28 20:32 UTC

Tell HN: An app is silently installing itself on my iPhone every day (news.ycombinator.com)

571 points|by _-x-_||186 comments|Read full story on news.ycombinator.com
Every day for the past 3 days around 1pm EST the 'Headspace' app has been silently appearing on my iPhone (13 Pro). Automatic downloads are turned off and I've updated to the latest iOS since this started happening.

I googled around and found a couple reddit threads with people reporting the exact same thing starting 2 or 3 days ago. There were reports from people on iPhone 12 and iPhone 17 so it doesn't seem device-specific.

Anyone else seeing this? Does anyone understand how or why this is happening?

Comments (186)

120 shown|More comments
  1. 1. psynixx||context
    I’ve been getting this too, same app same behaviour… Anyone been able to figure out what is causing this?
  2. 2. _-x-_||context
    Have you downloaded the app before?
  3. 3. throwaway5465||context
    Maybe a competitor is trying to FUD them?
  4. 4. _-x-_||context
    I would imagine that this isn't (or at least shouldn't be) possible based on Apple's security. The app is automatically downloading to my phone without my permission.
  5. 5. k310||context
    Did you ever install it, or Ginger?

    An app store search also turned up "Headspace Care" (Ginger)

    Ginger is now Headspace Care

    It would be beyond malware for an app to install itself, since there's that app store hurdle to leap. (IMO)

  6. 6. _-x-_||context
    I installed the app in March of last year, and then deleted it the same day because I didn't want to pay for the subscription
  7. 7. mandeepj||context
    How did you find that? Any notification?
  8. 8. _-x-_||context
    It just appears on my homescreen
  9. 9. rglover||context
    If you've ever installed any companion app on your desktop macOS, your phone will try to sync apps (I think the same with Apple TV). Caught me off guard a few times.
  10. 10. _-x-_||context
    No, I've never downloaded it on my desktop. It appears that I downloaded it onto my phone over a year ago (I got an email in my inbox), but didn't want to pay for it so I deleted it.
  11. 11. janstice||context
    Is your phone connected to some work mobile device management? I could imagine someone has a jinxed Jamf or intune rule that is pushing things out.
  12. 12. _-x-_||context
    No, this is my personal device. It has never been connected to any MDM.
  13. 13. Schiendelman||context
    Have you actually checked your device management settings?
  14. 14. teruakohatu||context
    Yes, there are alt app stores that try to get you to agree to installing a MDM
  15. 15. _-x-_||context
    Yes. In Settings > General > VPN & Device Management, it says 'Sign in to Work or School Account'. Is there a different device management setting that I should be looking at?
  16. 16. Schiendelman||context
    That's the one. I was worried you might have something you didn't know about!
  17. 17. _-x-_||context
    Here's a Reddit thread of other people experiencing the same issue: https://www.reddit.com/r/ios/comments/1su82sc/headspace_app_...
  18. 18. Bjartr||context
    Based on that I'd guess either a meditation app company has figured out how to circumvent a lot of controls put in place by Apple, or it's a bug on Apple's side
  19. 19. _-x-_||context
    Yeah, I think the latter is more likely than the former. Perhaps a server side bug that's silently downloading the app on any device that's installed it previously?
  20. 20. donkey_brains||context
    But why this one specific app and no others?
  21. 21. _-x-_||context
    Right, that's what confuses me the most. I was very surprised to find the reddit thread showing that other people are also having this specific app silently installed on their devices.
  22. 22. dd8601fn||context
    Makes me think something got jacked up adding/removing things from promotional bundles with other apps.

    It shouldn’t do that, obviously, but headspace does seem like it’s one that bundles “free” with a bunch of health insurance, education, etc.

    From a debugging perspective, without having Apples information, I kinda want to know if all affected users have some related health or education apps.

  23. 23. breppp||context
    Headspace leaves health data, that's where my first guess would be
  24. 24. layer8||context
    Maybe it’s Apple’s equivalent of Guru Meditation.
  25. 25. altairprime||context
    Maybe Apple typo’d an app id incorrectly for some iOS core app thing in 26.4.2 and the one-character error is this app? I don’t know that anyone’s done a ‘likelihood of collision’ analysis on appstore unique IDs yet. Certainly I could see iOS having a “must be on the device” system set up for apps like Phone and Settings that has a last-ditch of reinstalling it if somehow deleted. Would be especially interesting if some core app that can’t normally be deleted is currently unprotected (back up your device locally first!).
  26. 26. wincy||context
    Maybe it’s like that time Apple thought everyone wanted that awful free U2 album that they automatically added to everyone’s iTunes library. (I know this isn’t actually the case but it’s the funniest explanation)
  27. 27. theowaway||context
    that fucking thing still shows up on my phone from time to time. It's aural herpes
  28. 28. trinsic2||context
    I use VLC for my music. Did you know if you uninstall the music app you can't play music though another music app?
  29. 29. archon810||context
    Is this really true, I presume on iPhones? As an Android user, this sounds insane to me.
  30. 30. mattmaroon||context
    Can’t be sure it isn’t others. This a very large app, so it may just be the one that gets noticed the most.
  31. 31. trinsic2||context
    Maybe this is not the same thing but I had this happen to me with the ticktock app. It installed by itself. The only difference I can see between this situation and my own is I'm positive I never installed this app because I never used it.

    It only happened one time though. After I uninstalled it, it never came back.

  32. 32. a34729t||context
    Or it is a mandated backdoor, and someone internally objected, and made it easier to exploit than it should be, or leaked how to exploit it?
  33. 33. 8cvor6j844qw_d6||context
    > mandated backdoor

    Probably one from the repository of backdoors "accidentally" introduced or "never" discovered.

    The mechanism's there, just needs to be woven with other exploits.

  34. 34. jdiff||context
    Makes no sense for headspace to be using it if that were the case.
  35. 35. Barbing||context
    Conspiracy theory would get too convoluted:

    Rogue employee employs the backdoor for a major app with hopefully conscientious users who’ll report it online; hopes to force a fix.

    Or it was a social experiment and some dumb app reinstalls itself every day too but no one’s complained en masse yet! ;)

  36. 36. 0123456789ABCDE||context
    what's the more likely explanation though?
  37. 37. Barbing||context
    bug
  38. 38. joenot443||context
    My guess is it's a bug on the App Store side which will actually hurt Headspace in the long run. If this was a casino app I'd feel a bit differently, but I'd be shocked if someone at Headspace did this deliberately.

    I'm trying to imagine the headspace of a user who deletes an app, only to see it pop back the next morning. Probably not a very relaxing experience :)

  39. 39. cortesoft||context
    This is fascinating. I am very curious to find out what the actual cause of this turns out to be.
  40. 40. trueno||context
    same. i get blasted with ads for this app on whatever platform, never installed it myself. the amount of promotions + this = my underdeveloped brain is so ready to assume the worst here. been a while since i used my pitchfork & i'm here for the riot.

    if it is, in fact, something nefarious at play that would be a pretty crazy 2026 era exploit. but i'm certain it's a bug/artifact of some sort that, for whatever reason, affects this specific app.

  41. 41. powersnail||context
    Maybe the developer was using Headspace as part of the test data and it bled into production?

    It's hard to imagine what Headspace would like to achieve if this were an exploit executed by them. It's so salient, that it makes no sense to do on purpose. At least some portion of Apple employees and their families are going to be affected by this, and this would escalate to the legal department immediately.

    My money is on Apple being the buggy one here.

  42. 42. trueno||context
    > My money is on Apple being the buggy one here.

    Yeah I'm thinking some sort of test artifact bleeding into prod and subject so some nightly process is likely the case.

  43. 43. julianozen||context
    This seems like a good guess. Seems like it was deployed Thursday based on the app reviews
  44. 44. concinds||context
    I wish Apple released incident reports in cases like these. I hate that their secrecy obsession extends so far beyond hardware.
  45. 45. red_admiral||context
    I feel sorry for the headspace devs if it's really 100% Apple's fault.
  46. 46. 0123456789ABCDE||context
    when "explaining a thing, no more assumptions should be made than are necessary."

    could be an ios bug; a bug with the notification library they use, any other app behaving similarly?

    considering the possibility this was on purpose, they would risk getting banned from the appstore. no, they are not big enough to avoid that. so it's unlikely this was intentional.

  47. 47. dyauspitr||context
    It downloaded itself on my phone as well. I thought it was some quirk with the Apple Watch sync because I used to have headspace installed at some point and that automatically shows up on the Apple Watch but deleting an app on the iPhone doesn’t always delete the corresponding Apple Watch app. So if you open headspace on the Apple Watch I assumed it redownloaded itself on the iPhone.
  48. 48. bharat1010||context
    looks like, no where its safea anymore
  49. 49. altairprime||context
    There's an Apple discussions thread now, too: https://discussions.apple.com/thread/256288392

    Has 4 'me too'. Do go click that 'me too' button to report the issue if you're seeing it!

  50. 50. treexs||context
    this is the plot of Persona 5
  51. 51. rootsudo||context
    He can be the joker we need.
  52. 52. efilife||context
    how heavy of a spoiler is this? I wanted to play it
  53. 53. applfanboysbgon||context
    It's not really a spoiler. It is something that happens near the beginning of the game.
  54. 54. diegoperini||context
    If I am not mistaken, it's even shown in the marketing materials to build suspense.
  55. 55. makeitdouble||context
    It's covered in the first 10~20min or so of the game, and is really a minor side point.

    Off topic, put P5 as a game doesn't really care about spoilers much, there is one specific story telling gimmick that will screw with you if you're really sensitive to these kind of things.

  56. 56. a34729t||context
    I would call Apple support; you might even get an engineer call you back. I am sure they would love to know what the hell is going on.
  57. 57. yokuze||context
    Do you have Settings > Apps > App Store > (Automatic Downloads) App Downloads turned on?

    I noticed apps appearing on my Home Screen I’d never heard of before. Turns out with that setting and Family Purchase sharing turned on, every time my wife installed a new app, it installed on my phone too.

    That may not be your exact scenario, but I wonder if turning off that Automatic App Downloads setting (if enabled) changes anything. Could give you a clue, if so.

  58. 58. _-x-_||context
    App Downloads and App Updates are both turned off. I don't have anyone else's devices on my account, just me. Thank you for the suggestions though!
  59. 59. wallst07||context
    Even with auto downloads turned off, does it show up in your app library or as a purchased app?

    You can still have a app library with apps that "should be" downloaded, what happens if its removed from that list?

  60. 60. trinsic2||context
    Speaking of which. Under Cellular Data There is a setting right below Automatic Downloads call "App Downloads". I wonder if that works independently of whether or not Automatic Downloads is off. The only options are: Always allow, ask if over 200mb and always ask.
  61. 61. COFyumo||context
    I have the same exact thing happening. I deleted the app a few days ago when was surprised to see it in my app list.

    I had previously downloaded the app but and removed it because I never used it. A few days ago I noticed the app when browsing through my app list and thought maybe I didnt delete it properly, so I made sure to delete it. Then this morning my iPhone updated software versions and I found he Headpsace app again on my home, except this time it was grayed out and waiting for me to go on wifi to download.

    I just deleted it again but am equally dumbfounded

  62. 62. _-x-_||context
    That's interesting that it still showed up on your homescreen despite not being able to download
  63. 63. meloyc||context
    jailbreak phone?
  64. 64. _-x-_||context
    Negative
  65. 65. bastawhiz||context
    Do you have MDM enabled on your device? Does your company offer Headspace as a perk and some arcane set of sketchy business agreements led to auto install policy in your company's MDM solution?
  66. 66. _-x-_||context
    No MDM installed
  67. 67. 1659447091||context
    Do you use iCloud drive?

    This might be a stretch as I am taking a guess at the implementation, but apps can sync with iCloud Drive and I keep getting app folders showing up after telling it not sync but the prefs reset after certain states(not quite sure when/how)-- it then creates a new sync folder when interacting with the app again. (after having turned off sync and deleting the folder -- once it resets)

    I am wondering if that app had that feature (icloud drive syncing) and something of the reverse is happening. Where you have a document still on icloud drive from when you installed the app. Maybe there is some action or state change going on after interacting with drive on a mac or something similar. And now it's created the right circumstances for icloud drive to try and sync the file but there is no app on any device so it downloads the app instead since it's missing and there is some dangling file looking for its home.

  68. 68. _-x-_||context
    It still doesn't make sense why the app started silently downloading itself 3 days ago when I haven't had it installed in over a year. I do use iCloud drive but do not see anything related to the app inside of it.
  69. 69. 1659447091||context
    Did you update iOS before it started happening? Wondering if they may have introduced a regression that is now trying to re-sync everything after the last update (sync files may be hidden, I set files to always show)
  70. 70. _-x-_||context
    I updated after noticing the issue
  71. 71. DavideNL||context
    @_-x-_: "Settings > App Store > Show Install Confirmations > On".

    Maybe that helps?

  72. 72. garyfirestorm||context
    This setting does not exist on iOS 26.4.1
  73. 73. DavideNL||context
  74. 74. parker-3461||context
    I just checked that I could see it in the Settings App search bar, but it does not show up under the actual App Store settings page, might be an implementation bug related to user region.

    Edit 1: this was on iPadOS 26.3.1 (a) (23D771330a)

  75. 75. altairprime||context
    The iOS reviews for the app also confirm this story affecting others.
  76. 76. julianozen||context
    Looks like something was deployed Thursday evening. My bet is it’s some kind of test configuration for the App Store itself that just happened to pick headspace and it’s rolled into prod by accident
  77. 77. aaronbrethorst||context
    I wonder if U2, or Bono, has taken a significant stake in Headspace recently (kidding).
  78. 78. edbaskerville||context
    Deep cut
  79. 79. swiftcoder||context
    Jesus, I hope not. That happened just a few years ago... right?
  80. 80. stingraycharles||context
    Wasn’t that around the release of the iPhone X?
  81. 81. kaelwd||context
    iPhone X? That came out this year didn't it?
  82. 82. hnlmorg||context
    No, you’re thinking of the iPad Touch
  83. 83. ukuina||context
    I'm pretty sure it was last year, when the "no new features, bugfixes only" MacOS version was released.
  84. 84. dtech||context
    More than a decade ago
  85. 85. steve1977||context
    A 50th anniversary gift you mean?
  86. 86. meindnoch||context
    It was so fucking funny. I wonder what the engineer thought, who had to issue the SQL query which added Bono to literally everyone's collection. Like, I'm not surprised that management was so out of touch, but I'd expect the engineers to have a bit of common sense...
  87. 87. actionfromafar||context
    They follow orders, like soldiers do.
  88. 88. PunchyHamster||context
    What he was going to do, ignore management ? There is always someone else clueless or not caring enough to do it
  89. 89. baq||context
    And do what? Quit and have someone else execute the query for something that’s in the grand scheme of things irrelevant?
  90. 90. Barbing||context
    There’s only a 99% chance they would’ve been fired for refusing though right?
  91. 91. mort96||context
    I feel like that's the kind of thing it's easy to not recognise as a terrible idea until after it's done, because so much of what makes it a bad idea is a consequence of the rest of the system.

    Imagine if everything else surrounding the Apple ecosystem worked better. Imagine if people who don't actively use Apple Music never experienced Apple Music starting to play music by itself. Imagine if people who do use Apple Music never had an album play without being actively interacted with. Imagine if the album cover wasn't low-key softcore gay porn. Imagine if you could "uninstall" an album you own, like how you can uninstall an app you own and never ever see it again unless you actively go out of your way to search for it on the App Store.

    Would it still have been a violation of consent? Sure, yeah it would. But almost everything people complain about is related to how it starts to play when they don't want to (an issue with iOS/macOS and Apple Music that would be annoying regardless), or how the album cover sometimes unintentionally pops up on your screen (such as when you hit the play/pause button on Mac when macOS doesn't think that there's any active paused media, so macOS opens Apple Music), or how there is no way for them to get rid of the album once they own it. These things are pretty large problems regardless of Songs of Innocence.

    I can sort of understand an engineer thinking that surely there can't be any major downsides to just giving away a digital good. And if the rest of iOS, macOS's, Apple Music and the album itself didn't have all these issues, it wouldn't have been much of an issue. Again, it would've been a consent violation, but developers at tech companies aren't exactly known for valuing consent anyway and everyone would've certainly forgot it by now.

  92. 92. nottorp||context
    > Imagine if people who don't actively use Apple Music never experienced Apple Music starting to play music by itself.

    Nice dream. My wireless headphones act like in the manual when paired with my phone, but the buttons on them always start apple music when paired with my laptop instead of muting or controlling noise canceling.

  93. 93. basisword||context
    >> I feel like that's the kind of thing it's easy to not recognise as a terrible idea until after it's done

    I don't even think it was a terrible idea. It was just one of those things lots of people irrationally hooked on to. "We're giving you all a free record". Enough people made it 'bad' because people like to make a fuss. The only real issue with it was the inability to remove it which they later rectified.

  94. 94. mort96||context
    Eh no, sorry. The practical result is that a ton of people who have absolutely no interest in U2 has Songs of Innocence start playing when they don't want it. It plays when people turn on their cars. It plays when people connect to Bluetooth speakers. It plays when people want to resume Spotify playback but Spotify got killed in the background. It plays when people want to resume the YouTube video they were watching but macOS lost track of what's paused. It's a truly terrible idea in practice.

    Apple didn't really rectify the inability to remove it. They released a removal tool, but that tool is long defunct. The only way to remove it these days is to contact Apple Support, from what I can tell on the web.

  95. 95. kotaKat||context
    "We wanted to deliver a pint of milk to people's front porches, but in a few cases it ended up in their fridge, on their cereal. People were like, 'I'm dairy-free.'" -Bono

    Literally imagining the milk man bursting in to dump a gallon of milk on some poor sod's cereal this morning.

  96. 96. chihuahua||context
    Not only that, but the milk man also acts like he did them a huge favor. And hides his huge fortune in a tax haven, while relentlessly campaigning for the government to increase the tax burden on those who actually pay taxes.
  97. 97. Barbing||context
    Helped eliminate poverty, hmm:

    >Despite being well known for his extensive charity work, Bono has previously faced backlash over his tax dealings, with critics claiming that he could have helped to eliminate poverty if U2’s tax base remained based in Ireland.

    >Instead, it previously transpired that U2 often put their money through the Netherlands, where tax rates have reportedly resulted in increased profits for the Irish rock icons.

    >Two years ago, Bono dismissed the criticism as “just some smart people we have working for us trying to be sensible about the way we’re taxed. And that’s just one of our companies, by the way. There’s loads of companies”.

    https://www.nme.com/news/music/bono-releases-statement-named...

  98. 98. umanwizard||context
    Have you ever worked at a big company? There are plenty of people who don’t give a shit and just do whatever their boss tells them.
  99. 99. fmajid||context
    It's not good four my blood pressure to be reminded of that sanctimonious tax-dodging hypocrite.
  100. 100. andy_ppp||context
    Have you considered meditation? ;-)
  101. 101. ex-aws-dude||context
    I feel like I’m the only one who listened to that album when it appeared and thought it was pretty good
  102. 102. con||context
    Just checked and it also installed itself on my phone. iPhone 17 Pro, non-US App Store, on latest iOS beta, no MDM. Sounds like an Apple Store bug to me.
  103. 103. concinds||context
    Ever had it installed before? I wonder if that's a pattern.
  104. 104. con||context
    I did
  105. 105. DANmode||context
    Definitely the strongest pattern.
  106. 106. HoldOnAMinute||context
    I have never installed it, and currently don't have it installed.
  107. 107. NetOpWibby||context
    _Severance intensifies_
  108. 108. nkotov||context
    Had this happen as well. I haven’t used Headspace in years. Randomly had the app appear on Home Screen.
  109. 109. ddxv||context
    If anyone wants to browse some of the SDKs in headspace:

    https://appgoblin.info/apps/493145008/sdks

    I see normal development and tracking SDKs. If anyone sees something interesting let me know.

  110. 110. speedgoose||context
    The Facebook Ads SDK in a mental health app isn’t normal. Or shouldn’t.

    Even analytics SDKs is a bit weird to see. Are Amplitude or Sentry hosting data with a healthcare compliant infrastructure ? I won’t bet. Are those SDKs for sure not leaking health care data? It can be inadvertently, especially with Sentry. But I really wonder about why people feel the need to track so much. Do they **** in front of PowerPoint slides showing the tracking data or is it to sell user data?

  111. 111. rkachowski||context
    They are normal. They generally want to know if the ad spend resulted in an install. Health care data is radioactive and they would be fucking up very hard if sending this to an analytics service.
  112. 112. speedgoose||context
    I have seen studies where some apps were fucking up very hard and sending healthcare data to services that shouldn’t receive it. Sometimes in clear text.

    My trust is very low. Having healthcare data in a Sentry payload by mistake happens to the best of us.

  113. 113. hansvm||context
    Health care companies are radioactively affected by mishandling healthcare data (give or take practical impact being very toothless, especially nowadays). The data itself is mostly not an issue though under any legal theories, and if Joe Schmo hedge fund digs up your colon photos that's not usually an issue.
  114. 114. concinds||context
    I never thought there would be online SDK databases, what a useful resource in general. Thank you.
  115. 115. csomar||context
    > Does anyone understand how or why this is happening?

    They are drowning in tech debt. Here are two main issues I have with my iPhone/iOS: I can't search for the telegram app. It doesn't show up. It shows fine on the iPad. Also just a few minutes ago, app search decided not to work. I usually use it to pull my Wallet to pull my card. It was an awkward moment as I had no idea where the wallet app actually is.

    I have lost count of the minor polish issues. The experience has degraded so much that you no longer care.

  116. 116. snailmailman||context
    Regarding the telegram app I’d check iOS settings->apps->telegram->search and make sure “show app in search” is checked

    You can intentionally hide apps from search. If you did this, it’s not very obvious that its hidden from search unless you dig for the setting. Similarly, “hidden” apps refuse to show up in search results anywhere, even in settings.

  117. 117. nathanwh||context
    Thank you for this, I have wondered for more than a year why Google Maps would not show up when I searched for it.
  118. 118. csomar||context
    Thank you. I wonder how that happened as I was not aware such a feature existed.
  119. 119. pirates||context
    So then it’s not really any lack of polish or technical debt, just user error.
  120. 120. dagmx||context
    I’m curious if everyone experiencing this is on 26.4.2? It came out 4 days ago according to Wikipedia…it would make sense that it lines up with when people are seeing it start.

    I’m on the 26.5 beta and not seeing it at all.