AppReviewFix
Guideline library
Apple App StoreSafety

2.5.3Malware transmission

What this guideline means

This is Apple's baseline anti-malware rule — any code that behaves like a virus, spyware, or unauthorized remote-access tool, even bundled inside an otherwise legitimate app, is an automatic rejection.

Why apps actually get flagged

Almost always traced to a compromised or malicious third-party SDK pulled in through a dependency, rather than code the developer wrote themselves.

A real example

"Your app contains code designed to damage, disrupt, or gain unauthorized access to a device or network, per guideline 2.5.3."

Got this exact rejection?Paste it in and get a diagnosis specific to your app, free.
Decode my rejection
Related guidelines
5.1.1Data Collection and Storage4.3Spam2.1App Completeness
AppReviewFix
ProductDecoderPre-submission checkPricingGuideline library
CompanyAboutFAQContact
ResourcesBlog
LegalTermsPrivacy
© 2026 AppReviewFixBuilt by a developer, not a committee.