The question is: would such an attack work on Apple devices? I'm assuming that the iOS API provides similar functionality to apps running on the device.
The apps are probably removed from both stores by now so we will never know ;)
I saw the same attitude after the xcode backdoor. "There is no reason to believe any personal data has been affected", well if apple didn't even knew this thing existed how could they possibly know if it was activly used??
Edit: according to reddit apple just pulled all apps made by these guys. Not a proof of anything but still something to consider
So basically, maybe they put the adware in the iOS apps, maybe they didn't, but we can't tell from the article. But one would think that if they did, the article might have mentioned that, because it's a much better story to say "malware in the iOS app store" than it is to say "malware in the Google Play store".
(You didnt think apple would manually inspect billions of apps and their updates? 2 weeks per app * 1 billion apps * 3 updates = 115 million man years)
And your math is very wrong. Very few apps update every 2 weeks, most of the apps on the app store probably haven't even been updated in the past few months, and there's not even close to a billion apps. In an interview back in January Phil Schiller said the App Store had 2.2 million apps.
I assume it takes one person 2 weeks to fully analyze an app (we are after all looking for well hidden malware, possibly downloaded from network after some use). Times 2.2 million apps. Times an average of 3 updates during its life time.
There are not enough apple employees to pull what you calim. Hence approval is semi automatic, just like Google.
Edit: 1 billion changed to 2.2 million, my bad.
I feel you are just hiding your head in the sand instead of doing the sensible thing which is to ask apple to analyze this companys apps and report to public whether app store was affected.
But seriously, that's a fair point, my statement implied an unsourced assumption. I think Google tries to some extent, but I can't find anything saying Judy had anti-analysis capabilities, which makes me suspicious as to the effectiveness of Google's dynamic analysis of Play Apps.