RC RANDOM CHAOS

A red badge you never earned

Apple's persistent iOS ads and promotional prompts don't just annoy users - they erode the trust signal that protects you from Apple ID phishing.

· 7 min read
A red badge you never earned

The App Store on a current iPhone shows paid advertising in four places: the search tab before you type anything, the top of the results list, the Today feed, and near the bottom of individual app pages. That is Apple Search Ads, a business estimated to bring in several billion dollars a year. Running alongside it is a second stream most people fold into the same complaint: promotional notifications for Apple Music, Apple TV+, Arcade, Fitness+, iCloud+, and AppleCare. Those arrive as full-screen prompts inside Settings, banners in Wallet, and red badges on the App Store icon you never earned. None of it is malware. All of it degrades the one thing your phone’s security actually rests on - your ability to tell a genuine Apple prompt from a forged one.

What Apple is actually shipping

Two different systems get lumped together under the word “ads,” and the distinction is the whole story.

The first is the ad network. Advertisers bid to appear in the App Store. When you search “banking,” the paid slot above your bank’s real listing might be a competitor, or a lookalike. Apple labels these with a small blue “Ad” tag and a faint background tint. On a six-inch screen, in a hurry, that label is doing very little work.

The second is Apple marketing its own services through the operating system. Open Settings and you may hit a full-page pitch for iCloud+ storage. Finish a workout and get a notification for Fitness+. These are system-level messages - same fonts, same layout, same notification channel as the alerts that actually matter, like “your Apple ID was used to sign in on a new device.”

The reason to separate them: the first is a privacy story, the second is a security story, and the security story is the one almost nobody is pricing correctly.

The privacy cost is real but bounded

Apple’s ad targeting runs on data it already holds: your App Store search history, the apps you’ve downloaded, what you read in News and Stocks, and coarse location. Apple does not sell this to third parties the way a data broker does. Measured against the open-web ad economy, the privacy exposure from Apple Search Ads is smaller - the data stays inside Apple.

That is also the trap. Because Apple’s privacy posture is genuinely better than Google’s or Meta’s, users extend Apple unlimited trust, and unlimited trust is exactly what an attacker needs a target to have. The data leak is bounded. The trust it builds is not.

Habituation is the vulnerability

Security depends on a signal being rare. A prompt asking for your Apple ID password used to be uncommon - you saw it when you set up a device or bought something, and its rarity was itself information. If a password box appeared out of nowhere, that strangeness was a warning you could act on.

Persistent promotional prompts erase the rarity. When the OS interrupts you weekly to sell storage, pushes badges you didn’t request, and drops subscription offers into Settings, you learn a habit: Apple interrupts me, I tap to dismiss, I move on. You stop reading. Dismissing an Apple prompt becomes muscle memory.

That habit is the exploit. Phishing does not defeat cryptography; it defeats attention. Every legitimate-but-unearned interruption Apple adds lowers the attention a user brings to the next one - and the next one might not be from Apple.

How a phisher uses this

Walk the chain. An attacker sends an iMessage or email dressed as an Apple billing notice: “Your Apple Music subscription could not be renewed.” Two years ago that message fought against a user’s baseline expectation that Apple rarely nags about subscriptions. Today it matches the baseline exactly, because Apple nags about subscriptions constantly. The lure now looks like Tuesday.

The link opens a page that mimics the Apple ID sign-in. The user, trained by months of tapping through real Apple prompts without reading them, enters the password. If the attacker runs a real-time relay, they push the login through Apple’s actual site, trigger the genuine two-factor prompt on the user’s own screen, and harvest the code the user then types back into the fake page. Apple ID compromise hands over iCloud, Find My, photos, and often the reset keys to every other account tied to that email.

Nothing here is exotic. Kits that clone the Apple ID flow have circulated for years. What Apple changed is the base rate - how normal an unexpected Apple prompt feels. Raise that base rate and you raise the yield of every phishing campaign that borrows Apple’s look, without the attacker writing a single new line of code.

The dialog you cannot verify

There is a specific, ugly version of this. In 2017, developer Felix Krause showed that any app could draw a fake “Sign in to iTunes Store” password dialog that was pixel-identical to the real system one, because third-party apps can render the same alert style. The user has no reliable way to tell the app-drawn fake from the OS-drawn real one. The only defense was behavioral: real password prompts were rare and tied to a specific action you just took, so an out-of-context one was suspect on its face.

Apple’s own promotional prompts attack that last defense. Once the OS routinely shows you unprompted, out-of-context messages, “out of context” stops being a reliable marker of fraud. You have trained the user to accept exactly the pattern the attacker needs.

The ad slot above your bank

The ad network carries its own direct attack surface, separate from habituation. Because advertisers buy placement by keyword, a scam app can bid to sit above the legitimate one. Search your bank, a crypto wallet, or a password manager, and the top result - the paid one - is not guaranteed to be who you assume. This has happened repeatedly: fake wallet apps and lookalike authenticators bought their way to the top slot for high-value search terms, harvested seed phrases or credentials, and were pulled only after people lost money. Apple reviews apps, but review is not instant and scam developers rotate faster than takedowns. The paid slot converts because it sits above the real listing and wears the same chrome. Read the developer name on every result before you tap install, especially for anything that holds money or credentials. The “Ad” tag tells you the placement was paid for. It does not tell you the app is safe.

What you can turn off right now

You can’t strip Apple Search Ads out of the App Store, but you can cut the promotional stream and the targeting. On iOS:

  • Settings > Apps > App Store (on older versions, Settings > App Store): turn off Personalized Recommendations and In-App Ratings & Reviews.
  • Settings > Privacy & Security > Apple Advertising: turn off Personalized Ads. This does not remove ads; it stops Apple aiming them with your data.
  • Settings > Notifications: scroll to Apple’s own apps - Music, TV, Fitness, Wallet, Tips, App Store - and disable notifications for anything you don’t actively use. Tips and promotional badges are the usual offenders.
  • Settings > Notifications > (each Apple app) > turn off Badges to kill the unearned red dots.
  • For iCloud storage nags there is no clean toggle; treat any in-Settings upgrade pitch as marketing and dismiss it from the top, never by entering credentials.

Then set one behavioral rule that outlives all of it: never authenticate from a prompt you didn’t trigger. If a password or two-factor request appears and you didn’t just tap buy, sign in, or install, close it. Open Settings yourself, tap your name at the top, and check from there. A real problem is still there when you navigate to it by hand. A fake one dies the moment you refuse to feed it.

What Apple won’t fix, and why

The incentive runs the wrong way. Services - the bucket holding the App Store, subscriptions, iCloud, and advertising - is Apple’s fastest-growing segment, tens of billions of dollars a quarter, and the ads and prompts are how that segment keeps growing on a device it has already saturated with hardware. Asking Apple to stop interrupting you is asking it to throttle its highest-margin business. It won’t.

So the honest framing is not “Apple got greedy.” It’s that Apple’s revenue model now grows by spending down the exact asset its security model depends on: the user’s trained assumption that the OS speaks rarely and only when it matters. Every promotional prompt is a small withdrawal from that account. Phishers make their living on the balance.

The number to watch isn’t how many ads you see. It’s how many seconds you spend reading an Apple prompt before you tap. If that number is falling, the training is working - and it isn’t only Apple’s marketing team who benefits from a user who has stopped reading.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.