PSA: Apple's Podcasts App Could Be Enabling Malicious Content Delivery

Security researchers have identified suspicious activity in Apple's Podcasts app that could be used to deliver malicious content to users, based on a report by 404Media's Joseph Cox.

Apple Podcasts Award
Cox's report describes some odd experiences with the Podcasts app that certainly suggest something untoward is going on across both iOS and macOS versions. He says that over recent months, the app has automatically launched and displayed unusual podcasts without his input. On Mac and iPhone, the app has opened religion, spirituality, and education podcasts for no apparent reason, in some cases even launching themselves the moment Cox unlocked his device.

The podcasts in question often feature strange titles containing code fragments, URLs, and in some cases, attempts at cross-site scripting attacks.

Objective-See security expert Patrick Wardle told Cox he was able to replicate similar behavior, but in his case via a website. "Simply visiting a website is enough to trigger Podcasts to open (and load a podcast of the attacker's choosing), and unlike other external app launches on macOS, no prompt or user approval is required," Wardle told 404 Media.

One particularly concerning podcast apparently includes a link that redirects to a site attempting an XSS attack – a technique in which attackers inject malicious code into otherwise legitimate-looking websites. When visited, the site displays a pop-up acknowledging the XSS attempt.

Wardle notes that while this behavior isn't immediately dangerous on its own, it creates an effective delivery mechanism if vulnerabilities do exist within the Podcasts app. "The level of probing shows that adversaries are actively evaluating the Podcasts app as a potential target," he said.

The situation bears similarities to reports of Google Calendar spam from several years ago, where bad actors would add unsolicited events containing links or promotional content to users' calendars.

Apple did not respond to Cox's multiple requests for comment about the issue. Has the Podcasts app exhibited similar unusual behaviour in your experience? Let us know in the comments.

Popular Stories

samsung crease less foldable display ces 2026%402x

Foldable iPhone's Crease-Free Display Tech Spotted at CES 2026

Tuesday January 6, 2026 3:04 am PST by Tim Hardwick
CES 2026 has just provided a first glimpse of the folding display technology that Apple is expected to use in its upcoming foldable iPhone. At the event, Samsung Display briefly showcased its new crease-less foldable OLED panel beside a Galaxy Z Fold 7, and according to SamMobile, which saw the test booth before it was abruptly removed, the new panel "has no crease at all" in comparison. The ...
iphone 17 models

No iPhone 18 Launch This Year, Reports Suggest

Thursday January 1, 2026 8:43 am PST by Hartley Charlton
Apple is not expected to release a standard iPhone 18 model this year, according to a growing number of reports that suggest the company is planning a significant change to its long-standing annual iPhone launch cycle. Despite the immense success of the iPhone 17 in 2025, the iPhone 18 is not expected to arrive until the spring of 2027, leaving the iPhone 17 in the lineup as the latest...
Apple Card iPhone 16 Pro Feature

Apple Card Will Move From Goldman Sachs to JPMorgan Chase

Wednesday January 7, 2026 12:57 pm PST by Eric Slivka
JPMorgan Chase has reached a deal to take over operation of the Apple Card, reports The Wall Street Journal. Barring any "last minute hiccups," the deal should be announced shortly after over a year of negotiations. Reports began circulating over two years ago that current Apple Card issuer Goldman Sachs was looking to end its partnership with Apple as part of an effort to scale back on...
AirPods Pro 3 Year of the Horse Feature

Apple Launches Year of the Horse AirPods Pro 3 for Lunar New Year

Monday January 5, 2026 11:28 am PST by Juli Clover
Apple has designed a limited edition version of the AirPods Pro 3 to celebrate Lunar New Year, and customers in select countries can purchase them starting today. The Year of the Horse Special Edition AirPods Pro 3 feature a unique horse emoji character that's otherwise unavailable. Customers in China, Hong Kong, Taiwan, Malaysia, and Singapore are able to buy the AirPods, and they'll be...
Logitech MX Master 3S

Logitech Blames 'Inexcusable Mistake' After Certificate Expiry Breaks macOS Apps

Wednesday January 7, 2026 5:27 am PST by Tim Hardwick
Logitech users on macOS found themselves locked out of their mouse customizations yesterday after the company let a security certificate expire, breaking both its Logi Options+ and G HUB configuration apps. Logitech devices like its MX Master series mice and MX Keys keyboards stopped working properly as a result of the oversight, with users unable to access their custom scrolling setup,...
ChatGPT Health Integration Connectors Feature

OpenAI Launches ChatGPT Health With Apple Health Integration

Wednesday January 7, 2026 11:27 am PST by Eric Slivka
OpenAI today announced the launch of ChatGPT Health, a dedicated section of ChatGPT where users can ask health-related questions completely separated from their main ChatGPT experience. For more personalized responses, users can connect various health data services such as Apple Health, Function, MyFitnessPal, Weight Watchers, AllTrails, Instacart, and Peloton. Last month, MacRumors discovere...
m4 macbook air blue 2

iPadOS and macOS 26.2 Double 5GHz Wi-Fi Bandwidth for Wi-Fi 6E Devices

Monday January 5, 2026 1:57 pm PST by Juli Clover
With the release of iPadOS 26.2 and macOS Tahoe 26.2, Apple has improved the Wi-Fi speeds for select Macs and iPads that support Wi-Fi 6E. Updated Wi-Fi connectivity specifications are listed in Apple's platform deployment guide. The M4 iPad Pro models, M3 iPad Air models, A17 Pro iPad mini, M2 to M5 MacBook Pro models, M2, M3, and M4 MacBook Air models, and other Wi-Fi 6E Macs and iPads now ...
anker new charger 2026

Anker Introduces Pre-Order Discounts on 2026 Nano Chargers, Alongside Big New Year's Sale

Monday January 5, 2026 10:17 am PST by Mitchel Broussard
Anker announced a new series of products at CES this week, and most of them will begin rolling out to customers later in January. A few of these devices, including the Nano Docking Station and 45W Nano Charger, have pre-order discounts on Anker's website, and we're also tracking big discounts in Anker's New Year's sale. Note: MacRumors is an affiliate partner with some of these vendors. When...

Top Rated Comments

WarmWinterHat Avatar
6 weeks ago

Hmmm, they must've missed this one..
No app review process on internally produced apps, like Podcasts.

Hence why they can violate half the rules they make others follow. ?
Score: 7 Votes (Like | Disagree)
Danilamak Avatar
6 weeks ago
Side loading is a huge threat they say
Score: 6 Votes (Like | Disagree)
Mrkevinfinnerty Avatar
6 weeks ago

“Through the App Review process, we work to ensure apps come from vetted sources and are free of known malicious components. We also check that the apps aren’t trying to trick you into making unwanted purchases or providing access to personal data. We screen developers and users, expelling those who misbehave.
Hmmm, they must've missed this one..
Score: 4 Votes (Like | Disagree)
Edd70 Avatar
6 weeks ago
Didn’t need new reasons to not use that app.
Score: 4 Votes (Like | Disagree)
klasma Avatar
6 weeks ago

Side loading is a huge threat they say
Their preferential treatment of their own apps probably compels them to not implement certain security measures wholesale at the iOS level.
Score: 3 Votes (Like | Disagree)
CarAnalogy Avatar
6 weeks ago

No app review process on internally produced apps, like Podcasts.

Hence why they can violate half the rules they make others follow. ?
In fact it seems the opposite, the marketing team gets to insert ads and popups everywhere in Apple’s own apps these days.
Score: 3 Votes (Like | Disagree)