# Adware Doctor App Exfiltrates Mac Browser History

Published: 2026-08-02 · Severity: medium
Canonical: https://vorant.io/reports/1e346de5-4bfd-5cd7-933d-cea4e6e73f6e/adware-doctor-app-exfiltrates-mac-browser-history

> Adware Doctor, a top-grossing Mac App Store utility, secretly collected users' Safari, Chrome and Firefox history plus system data and uploaded it to remote servers.

Researchers found that Adware Doctor, a paid anti-adware utility that ranked as the #4 top-grossing app and #1 paid utility in the official Mac App Store, was secretly harvesting and exfiltrating sensitive user data. Despite running inside Apple's App Sandbox, the app abused a user-granted file-access entitlement (obtained under the guise of legitimate adware scanning) to read Safari, Chrome and Firefox history databases, App Store search history, a list of downloaded installers, and system/process information. It then zipped this data into a password-protected archive and uploaded it over HTTPS to yelabapp.com infrastructure via an API endpoint named 'checkadware'.

Analysis of the binary revealed the app also circumvented sandbox restrictions on process enumeration (normally blocking /bin/ps) by directly invoking sysctl/KERN_PROC_ALL logic copied from Apple's own sample code, a technique that should not be permitted for sandboxed App Store apps. The app has a documented history of AppleScript abuse, name-squatting on a competitor's brand, and fake reviews, and its developer identity ('Yongming Zhang') could not be substantively verified. Despite being reported to Apple roughly a month prior, the app remained available until public disclosure forced its removal, raising concerns about the effectiveness of Apple's App Store review and vetting process.

The exfiltration endpoint (adscan.yelabapp.com) went offline shortly before publication, though the app's local collection logic remained active and could resume exfiltration if the endpoint were restored. The incident illustrates how App Store review can miss sandbox-bypass techniques and covert data collection even in top-grossing, widely trusted applications.

## Mentioned in this report

- Threat actors: Yongming Zhang
- Malware: Adware Doctor

Source reporting: https://objective-see.org/blog/blog_0x37.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1e346de5-4bfd-5cd7-933d-cea4e6e73f6e/adware-doctor-app-exfiltrates-mac-browser-history.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
