The App Store review process remains broken.

This complaint is nothing new; developers have railed against the pains of App Store review for as long as there’s been an App Store. The fact that some humans (and, I’d expect, some automated tools) vet every single update from every single developer — including developers who’ve shipped dozens of approved updates over a decade or more — is frankly bonkers, not to mention error-prone. Though allegedly focused on benefiting users (through better safety and compliance), App Store review in its current form mostly frustrates the people it claims to protect.

Just to make sure we’re on the same page: Every single app and app update released in the App Store goes through this review process, and the review process is largely a black box. Developers submit, and then wait. They are given no specific timeline or indication of how long the review will take, and it’s inconsistent. Some reviews happen in hours. Some take days. When you’re rejected, you can reply to Apple, make fixes and resubmit, or appeal — and whichever path you pick, you’re waiting again, with no specific timelines provided from Apple.

And the review process is far from perfect.

Those are all scammy apps that got through. Apple’s review capacity isn’t infinite. Every hour a reviewer spends poring over a bug-fix update to an app that’s been in the store for years is an hour not spent catching the fake LastPass app.

I’ve already complained about TestFlight reviews, which genuinely make no sense at all. With new app submissions — and even, I suppose, with updates — I understand that Apple wants to prevent rogue apps from getting into the App Store. I’m talking about apps that do harm, or steal data, or do other bad things.

But do we really think that, say, Tapbots — after all this time — is going to sneak an update into Ivory that secretly mines bitcoin against the user’s will in the background?

And the review process is fundamentally flawed anyway: It works best with developers who are trying to do the right thing. Plenty of apps pull their content, features, and behavior from servers their developers control. Feature flags, remote configuration, and web views mean an app can behave differently the day after approval than it did the day of vetting. A determined bad actor can get past App Review. An honest developer just waits in a slow, nebulous line.

I submitted a slew of updates to Strategery after its major 4.0 update. Some took hours to get reviewed, which isn’t terrible. Some took days. When a vision-impaired player told me about a tweak that would significantly improve my VoiceOver implementation, I was happy to do it. I was frustrated that it took a couple days for him to get to use it after the update was done.

Apple already built the lighter version

Apple knows how to do a lighter-touch review. It already does one.

On the Mac, apps distributed outside the Mac App Store go through notarization. Apple scans them for malware in an automated process that typically takes minutes, and no human reviewer ever looks at them. In the EU, where the law forced Apple to allow alternative app marketplaces, iOS apps distributed through those marketplaces get notarized too — a pared-down review focused on security and basic functionality, not the full App Store rulebook.

So Apple has already decided, twice, that lighter review is safe enough. It just won’t offer it to the developers who’ve clearly earned it.

To be fair, Apple sort of saw some of this coming. At WWDC 2020, the company announced that bug fixes for apps already in the App Store would no longer be held up over guideline violations (except for legal issues); developers could address those problems in a subsequent update instead. That’s a good policy! Based on developer complaints I’ve seen, Apple hasn’t honored that agreement. It’s also not the core problem. A bug fix that Apple will definitely approve still sits in the same queue, for the same unpredictable stretch of time, as everything else.

What a Trusted Developer Program should look like

The lack of a Trusted Developer Program is a significant miss on Apple’s part. Developers who consistently release apps that Apple has consistently approved should at a bare minimum be able to get their app updates whitelisted. If Apple still wants to vet those apps, the company should do so “in arrears,” after the app’s live. And in the case of a “rejection” over some guideline nitpick, Apple shouldn’t simply revert the app — that would, again, suck for everyone — but rather, tell the developer what needs to get tweaked in a subsequent update. Give the developer a deadline if need be.

If an update genuinely harms users — say, a compromised third-party SDK starts siphoning off data — sure, pull it. Apple can already yank apps from the store at any time, and it should keep that power. That’s what makes after-the-fact review reasonable.

The obvious objection is that trusted status becomes something scammers want to buy or steal. That’s happened with browser extensions: A popular, well-behaved extension gets sold to a shady buyer, who promptly pushes out an update that does something nasty. Fine. Trust should belong to the developer, not the app, and it should evaporate the moment an app changes hands. Tie it to two-factor authentication and whatever account signals Apple already watches. This isn’t hard for a company with Apple’s near-infinite resources.

But the current approach means bug fixes, enhancements, and other improvements take too long to get into users’ hands — even though most updates from most developers do end up getting approved most of the time.

I know that Apple isn’t only worried about nefarious actions that do specific harm; the company also worries about developers bypassing other App Store regulations about in-app purchases and messaging and all that. But that’s business enforcement, not user safety, and it shouldn’t hold up a bug fix. (It’s also a weaker rationale than it used to be: Since the April 2025 ruling in Epic’s lawsuit, Apple can’t stop US apps from pointing users to purchases on the web anyway.)

Apple’s “guilty until proven innocent” policy is offensive to the developers it claims to embrace. But the part that stings most is what users see. When a fix takes a week to arrive, users don’t blame App Review. Most of them have never heard of App Review. They blame the developer. Making users wait for fixes and improvements makes app makers look slow, when it’s often Cupertino that’s causing the holdups.