Just checked and it also installed itself on my phone. iPhone 17 Pro, non-US App Store, on latest iOS beta, no MDM. Sounds like an Apple Store bug to me.
Based on that I'd guess either a meditation app company has figured out how to circumvent a lot of controls put in place by Apple, or it's a bug on Apple's side
Yeah, I think the latter is more likely than the former. Perhaps a server side bug that's silently downloading the app on any device that's installed it previously?
Right, that's what confuses me the most. I was very surprised to find the reddit thread showing that other people are also having this specific app silently installed on their devices.
This might be a stretch as I am taking a guess at the implementation, but apps can sync with iCloud Drive and I keep getting app folders showing up after telling it not sync but the prefs reset after certain states(not quite sure when/how)-- it then creates a new sync folder when interacting with the app again. (after having turned off sync and deleting the folder -- once it resets)
I am wondering if that app had that feature (icloud drive syncing) and something of the reverse is happening. Where you have a document still on icloud drive from when you installed the app. Maybe there is some action or state change going on after interacting with drive on a mac or something similar. And now it's created the right circumstances for icloud drive to try and sync the file but there is no app on any device so it downloads the app instead since it's missing and there is some dangling file looking for its home.
It still doesn't make sense why the app started silently downloading itself 3 days ago when I haven't had it installed in over a year. I do use iCloud drive but do not see anything related to the app inside of it.
Do you have Settings > Apps > App Store > (Automatic Downloads) App Downloads turned on?
I noticed apps appearing on my Home Screen I’d never heard of before. Turns out with that setting and Family Purchase sharing turned on, every time my wife installed a new app, it installed on my phone too.
That may not be your exact scenario, but I wonder if turning off that Automatic App Downloads setting (if enabled) changes anything. Could give you a clue, if so.
I have the same exact thing happening. I deleted the app a few days ago when was surprised to see it in my app list.
I had previously downloaded the app but and removed it because I never used it. A few days ago I noticed the app when browsing through my app list and thought maybe I didnt delete it properly, so I made sure to delete it. Then this morning my iPhone updated software versions and I found he Headpsace app again on my home, except this time it was grayed out and waiting for me to go on wifi to download.
I just deleted it again but am equally dumbfounded
Do you have MDM enabled on your device? Does your company offer Headspace as a perk and some arcane set of sketchy business agreements led to auto install policy in your company's MDM solution?
Yes. In Settings > General > VPN & Device Management, it says 'Sign in to Work or School Account'. Is there a different device management setting that I should be looking at?
If you've ever installed any companion app on your desktop macOS, your phone will try to sync apps (I think the same with Apple TV). Caught me off guard a few times.
No, I've never downloaded it on my desktop. It appears that I downloaded it onto my phone over a year ago (I got an email in my inbox), but didn't want to pay for it so I deleted it.
I would imagine that this isn't (or at least shouldn't be) possible based on Apple's security. The app is automatically downloading to my phone without my permission.
And before anyone accuses me of being paranoid, this should have never been possible.
The fact that it’s happening shows that they always had the ability and either made a mistake to show their hand now or stopped giving a shit if we cared.
Why did a mental healthcare company have the ability to exploit this?
Do you think they accidentally found this 5 seconds before their exploit was launched or do you think they might have actually put some effort into doing this since they are an organization of people.
Just checked and it also installed itself on my phone. iPhone 17 Pro, non-US App Store, on latest iOS beta, no MDM. Sounds like an Apple Store bug to me.
Here's a Reddit thread of other people experiencing the same issue: https://www.reddit.com/r/ios/comments/1su82sc/headspace_app_...
This is fascinating. I am very curious to find out what the actual cause of this turns out to be.
Based on that I'd guess either a meditation app company has figured out how to circumvent a lot of controls put in place by Apple, or it's a bug on Apple's side
Or it is a mandated backdoor, and someone internally objected, and made it easier to exploit than it should be, or leaked how to exploit it?
> mandated backdoor
Probably one from the repository of backdoors "accidentally" introduced or "never" discovered.
The mechanism's there, just needs to be woven with other exploits.
Yeah, I think the latter is more likely than the former. Perhaps a server side bug that's silently downloading the app on any device that's installed it previously?
But why this one specific app and no others?
Headspace leaves health data, that's where my first guess would be
Right, that's what confuses me the most. I was very surprised to find the reddit thread showing that other people are also having this specific app silently installed on their devices.
I wonder if U2, or Bono, has taken a significant stake in Headspace recently (kidding).
Do you use iCloud drive?
This might be a stretch as I am taking a guess at the implementation, but apps can sync with iCloud Drive and I keep getting app folders showing up after telling it not sync but the prefs reset after certain states(not quite sure when/how)-- it then creates a new sync folder when interacting with the app again. (after having turned off sync and deleting the folder -- once it resets)
I am wondering if that app had that feature (icloud drive syncing) and something of the reverse is happening. Where you have a document still on icloud drive from when you installed the app. Maybe there is some action or state change going on after interacting with drive on a mac or something similar. And now it's created the right circumstances for icloud drive to try and sync the file but there is no app on any device so it downloads the app instead since it's missing and there is some dangling file looking for its home.
It still doesn't make sense why the app started silently downloading itself 3 days ago when I haven't had it installed in over a year. I do use iCloud drive but do not see anything related to the app inside of it.
Did you update iOS before it started happening?
Do you have Settings > Apps > App Store > (Automatic Downloads) App Downloads turned on?
I noticed apps appearing on my Home Screen I’d never heard of before. Turns out with that setting and Family Purchase sharing turned on, every time my wife installed a new app, it installed on my phone too.
That may not be your exact scenario, but I wonder if turning off that Automatic App Downloads setting (if enabled) changes anything. Could give you a clue, if so.
App Downloads and App Updates are both turned off. I don't have anyone else's devices on my account, just me. Thank you for the suggestions though!
I have the same exact thing happening. I deleted the app a few days ago when was surprised to see it in my app list.
I had previously downloaded the app but and removed it because I never used it. A few days ago I noticed the app when browsing through my app list and thought maybe I didnt delete it properly, so I made sure to delete it. Then this morning my iPhone updated software versions and I found he Headpsace app again on my home, except this time it was grayed out and waiting for me to go on wifi to download.
I just deleted it again but am equally dumbfounded
That's interesting that it still showed up on your homescreen despite not being able to download
Do you have MDM enabled on your device? Does your company offer Headspace as a perk and some arcane set of sketchy business agreements led to auto install policy in your company's MDM solution?
No MDM installed
Is your phone connected to some work mobile device management? I could imagine someone has a jinxed Jamf or intune rule that is pushing things out.
No, this is my personal device. It has never been connected to any MDM.
Have you actually checked your device management settings?
Yes. In Settings > General > VPN & Device Management, it says 'Sign in to Work or School Account'. Is there a different device management setting that I should be looking at?
That's the one. I was worried you might have something you didn't know about!
Yes, there are alt app stores that try to get you to agree to installing a MDM
@_-x-_: "Settings > App Store > Show Install Confirmations > On".
Maybe that helps?
The iOS reviews for the app also confirm this story affecting others.
I would call Apple support; you might even get an engineer call you back. I am sure they would love to know what the hell is going on.
Did you ever install it, or Ginger?
An app store search also turned up "Headspace Care" (Ginger)
Ginger is now Headspace Care
It would be beyond malware for an app to install itself, since there's that app store hurdle to leap. (IMO)
I installed the app in March of last year, and then deleted it the same day because I didn't want to pay for the subscription
If you've ever installed any companion app on your desktop macOS, your phone will try to sync apps (I think the same with Apple TV). Caught me off guard a few times.
No, I've never downloaded it on my desktop. It appears that I downloaded it onto my phone over a year ago (I got an email in my inbox), but didn't want to pay for it so I deleted it.
this is the plot of Persona 5
He can be the joker we need.
how heavy of a spoiler is this? I wanted to play it
It's not really a spoiler. It is something that happens near the beginning of the game.
How did you find that? Any notification?
It just appears on my homescreen
I’ve been getting this too, same app same behaviour… Anyone been able to figure out what is causing this?
Have you downloaded the app before?
jailbreak phone?
Negative
Maybe a competitor is trying to FUD them?
I would imagine that this isn't (or at least shouldn't be) possible based on Apple's security. The app is automatically downloading to my phone without my permission.
Guess the corporations are taking the mask off.
And before anyone accuses me of being paranoid, this should have never been possible.
The fact that it’s happening shows that they always had the ability and either made a mistake to show their hand now or stopped giving a shit if we cared.
At least they're exposing their nefarious plans for the purposes of... Offering people mental healthcare?
It's probably just some Apple bug.
Why did a mental healthcare company have the ability to exploit this?
Do you think they accidentally found this 5 seconds before their exploit was launched or do you think they might have actually put some effort into doing this since they are an organization of people.