If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…
5) The whole point of this proof-of-concept seems to be to have unsuspecting, innocent devs who build regular boring apps, like Tinder For Dogs or whatever, unknowingly build the app using poisoned XCode. That way, when Mr. Bad Guy eventually installs Tinder For Dogs on his iPhone, the CIA gets a secret backdoor to his entire phone.
But this seems so overly complicated! If the CIA already has a payload that phones home, why didn't they just build their own apps? Why rely on poisoning a dev environment in the vague hope that Mr. Bad Guy will someday download this particular app? What if Mr. Bad Guy doesn't even have a dog?
Also, I wrote above that an intelligence agency would not likely be interested in getting data from something like a single-player game. There's probably nothing useful to learn about there, other than Mr. Bad Guy's high score.
But maybe that dumb game was the Trojan, not the target. Mr. Bad Guy may be too smart to use SnapChat, but perhaps he installed FarmVille or Angry Birds to while away the hours...?