113

Tell HN: An app is silently installing itself on my iPhone every day

Every day for the past 3 days around 1pm EST the 'Headspace' app has been silently appearing on my iPhone (13 Pro). Automatic downloads are turned off and I've updated to the latest iOS since this started happening.

I googled around and found a couple reddit threads with people reporting the exact same thing starting 2 or 3 days ago. There were reports from people on iPhone 12 and iPhone 17 so it doesn't seem device-specific.

Anyone else seeing this? Does anyone understand how or why this is happening?

Here's a Reddit thread of other people experiencing the same issue: https://www.reddit.com/r/ios/comments/1su82sc/headspace_app_...

3 hours ago_-x-_

This is fascinating. I am very curious to find out what the actual cause of this turns out to be.

an hour agocortesoft

same. i get blasted with ads for this app on whatever platform, never installed it myself. the amount of promotions + this = my underdeveloped brain is so ready to assume the worst here. been a while since i used my pitchfork & i'm here for the riot.

if it is, in fact, something nefarious at play that would be a pretty crazy 2026 era exploit. but i'm certain it's a bug/artifact of some sort that, for whatever reason, affects this specific app.

17 minutes agotrueno

Based on that I'd guess either a meditation app company has figured out how to circumvent a lot of controls put in place by Apple, or it's a bug on Apple's side

3 hours agoBjartr

Or it is a mandated backdoor, and someone internally objected, and made it easier to exploit than it should be, or leaked how to exploit it?

2 hours agoa34729t

> mandated backdoor

Probably one from the repository of backdoors "accidentally" introduced or "never" discovered.

The mechanism's there, just needs to be woven with other exploits.

an hour ago8cvor6j844qw_d6

Yeah, I think the latter is more likely than the former. Perhaps a server side bug that's silently downloading the app on any device that's installed it previously?

3 hours ago_-x-_

But why this one specific app and no others?

2 hours agodonkey_brains

[delayed]

6 minutes agoaltairprime

Maybe it’s Apple’s equivalent of Guru Meditation.

22 minutes agolayer8

Right, that's what confuses me the most. I was very surprised to find the reddit thread showing that other people are also having this specific app silently installed on their devices.

2 hours ago_-x-_

Headspace leaves health data, that's where my first guess would be

43 minutes agobreppp

[dead]

an hour agoaaron695

I wonder if U2, or Bono, has taken a significant stake in Headspace recently (kidding).

an hour agoaaronbrethorst

I’m curious if everyone experiencing this is on 26.4.2? It came out 4 days ago according to Wikipedia…it would make sense that it lines up with when people are seeing it start.

I’m on the 26.5 beta and not seeing it at all.

7 minutes agodagmx

Do you have Settings > Apps > App Store > (Automatic Downloads) App Downloads turned on?

I noticed apps appearing on my Home Screen I’d never heard of before. Turns out with that setting and Family Purchase sharing turned on, every time my wife installed a new app, it installed on my phone too.

That may not be your exact scenario, but I wonder if turning off that Automatic App Downloads setting (if enabled) changes anything. Could give you a clue, if so.

2 hours agoyokuze

App Downloads and App Updates are both turned off. I don't have anyone else's devices on my account, just me. Thank you for the suggestions though!

2 hours ago_-x-_

Do you use iCloud drive?

This might be a stretch as I am taking a guess at the implementation, but apps can sync with iCloud Drive and I keep getting app folders showing up after telling it not sync but the prefs reset after certain states(not quite sure when/how)-- it then creates a new sync folder when interacting with the app again. (after having turned off sync and deleting the folder -- once it resets)

I am wondering if that app had that feature (icloud drive syncing) and something of the reverse is happening. Where you have a document still on icloud drive from when you installed the app. Maybe there is some action or state change going on after interacting with drive on a mac or something similar. And now it's created the right circumstances for icloud drive to try and sync the file but there is no app on any device so it downloads the app instead since it's missing and there is some dangling file looking for its home.

an hour ago1659447091

It still doesn't make sense why the app started silently downloading itself 3 days ago when I haven't had it installed in over a year. I do use iCloud drive but do not see anything related to the app inside of it.

an hour ago_-x-_

Did you update iOS before it started happening? Wondering if they may have introduced a regression that is now trying to re-sync everything after the last update (sync files may be hidden, I set files to always show)

an hour ago1659447091

I updated after noticing the issue

31 minutes ago_-x-_

I have the same exact thing happening. I deleted the app a few days ago when was surprised to see it in my app list.

I had previously downloaded the app but and removed it because I never used it. A few days ago I noticed the app when browsing through my app list and thought maybe I didnt delete it properly, so I made sure to delete it. Then this morning my iPhone updated software versions and I found he Headpsace app again on my home, except this time it was grayed out and waiting for me to go on wifi to download.

I just deleted it again but am equally dumbfounded

2 hours agoCOFyumo

That's interesting that it still showed up on your homescreen despite not being able to download

an hour ago_-x-_

The iOS reviews for the app also confirm this story affecting others.

an hour agoaltairprime

Is your phone connected to some work mobile device management? I could imagine someone has a jinxed Jamf or intune rule that is pushing things out.

4 hours agojanstice

No, this is my personal device. It has never been connected to any MDM.

3 hours ago_-x-_

Have you actually checked your device management settings?

3 hours agoSchiendelman

Yes. In Settings > General > VPN & Device Management, it says 'Sign in to Work or School Account'. Is there a different device management setting that I should be looking at?

3 hours ago_-x-_

That's the one. I was worried you might have something you didn't know about!

2 hours agoSchiendelman

Yes, there are alt app stores that try to get you to agree to installing a MDM

3 hours agoteruakohatu

I would call Apple support; you might even get an engineer call you back. I am sure they would love to know what the hell is going on.

2 hours agoa34729t

Did you ever install it, or Ginger?

An app store search also turned up "Headspace Care" (Ginger)

Ginger is now Headspace Care

It would be beyond malware for an app to install itself, since there's that app store hurdle to leap. (IMO)

4 hours agok310

I installed the app in March of last year, and then deleted it the same day because I didn't want to pay for the subscription

3 hours ago_-x-_

Do you have MDM enabled on your device? Does your company offer Headspace as a perk and some arcane set of sketchy business agreements led to auto install policy in your company's MDM solution?

an hour agobastawhiz

No MDM installed

an hour ago_-x-_

Had this happen as well. I haven’t used Headspace in years. Randomly had the app appear on Home Screen.

26 minutes agonkotov

Just checked and it also installed itself on my phone. iPhone 17 Pro, non-US App Store, on latest iOS beta, no MDM. Sounds like an Apple Store bug to me.

43 minutes agocon

@_-x-_: "Settings > App Store > Show Install Confirmations > On".

Maybe that helps?

an hour agoDavideNL

This setting does not exist on iOS 26.4.1

19 minutes agogaryfirestorm

If you've ever installed any companion app on your desktop macOS, your phone will try to sync apps (I think the same with Apple TV). Caught me off guard a few times.

4 hours agorglover

No, I've never downloaded it on my desktop. It appears that I downloaded it onto my phone over a year ago (I got an email in my inbox), but didn't want to pay for it so I deleted it.

3 hours ago_-x-_

_Severance intensifies_

35 minutes agoNetOpWibby

this is the plot of Persona 5

2 hours agotreexs

He can be the joker we need.

2 hours agorootsudo

how heavy of a spoiler is this? I wanted to play it

an hour agoefilife

It's covered in the first 10~20min or so of the game, and is really a minor side point.

Off topic, put P5 as a game doesn't really care about spoilers much, there is one specific story telling gimmick that will screw with you if you're really sensitive to these kind of things.

12 minutes agomakeitdouble

It's not really a spoiler. It is something that happens near the beginning of the game.

44 minutes agoapplfanboysbgon

If I am not mistaken, it's even shown in the marketing materials to build suspense.

21 minutes agodiegoperini

How did you find that? Any notification?

4 hours agomandeepj

It just appears on my homescreen

4 hours ago_-x-_

> Does anyone understand how or why this is happening?

They are drowning in tech debt. Here are two main issues I have with my iPhone/iOS: I can't search for the telegram app. It doesn't show up. It shows fine on the iPad. Also just a few minutes ago, app search decided not to work. I usually use it to pull my Wallet to pull my card. It was an awkward moment as I had no idea where the wallet app actually is.

I have lost count of the minor polish issues. The experience has degraded so much that you no longer care.

19 minutes agocsomar

I’ve been getting this too, same app same behaviour… Anyone been able to figure out what is causing this?

5 hours agopsynixx

Have you downloaded the app before?

3 hours ago_-x-_

jailbreak phone?

2 hours agomeloyc

Negative

an hour ago_-x-_
[deleted]
3 hours ago

Maybe a competitor is trying to FUD them?

4 hours agothrowaway5465
[deleted]
28 minutes ago

I would imagine that this isn't (or at least shouldn't be) possible based on Apple's security. The app is automatically downloading to my phone without my permission.

3 hours ago_-x-_

[dead]

3 hours agoxinji-standard

[flagged]

2 hours agolovich

At least they're exposing their nefarious plans for the purposes of... Offering people mental healthcare?

It's probably just some Apple bug.

2 hours agoanon84873628

Why did a mental healthcare company have the ability to exploit this?

Do you think they accidentally found this 5 seconds before their exploit was launched or do you think they might have actually put some effort into doing this since they are an organization of people.

an hour agolovich

I am pretty skeptical it’s intentional. Very risky move. If they make apple look bad they can say goodbye to getting featured in the app store, or could even get pulled from the store completely.

I can see a fucked up ceo greenlighting a trick to get their app installed on your phone without asking. I can’t really see them having it repeatedly download.

I suspect it’s a bug, or worst case a backdoor that’s been triggered with a commercial app instead of spyware accidentally or “accidentally”.

38 minutes agokennywinker

I cannot possibly imagine the company as a whole would approve of this, much less anyone at the company who wants to keep their job. If it’s found that they exploited Apple to cause this, Apple might force-remove their app worldwide and definitely will kill their developer account pending any lawsuits. That’s the sort of thing that gets a CMO fired. Seems extremely unlikely, but if their C_O gets fired on Monday or Friday, then we’ll probably know why :D

24 minutes agoaltairprime

> The fact that it’s happening shows that they always had the ability...

That may not be the case here, and certainly isn't the assumption we can make more generally.

We regularly see regressions in platform security.

39 minutes agofirecall

[flagged]

2 hours agolovich

Please don't comment about the voting on comments. It never does any good, and it makes boring reading.

https://news.ycombinator.com/newsguidelines.html

2 hours agoslater

When this forum handles the bot and propaganda problem I might consider those rules.

Currently we are inundated by accounts who don’t give a shit and make a new automatically 3 seconds after their flagging.

As long as those accounts are allowed I don’t really care for the stated rules that aren’t actually enforced.