Malware · guide
Can iPhones get viruses, and what happens instead
By Alberto Gulotta · Updated · 16 min read
Can iPhones get viruses in the strict sense — software that copies itself from app to app — effectively no, and the reason is a mechanism rather than a reputation. Malicious software of other kinds does reach them, Apple publishes how much it blocks, and what is behind the question is one of four things, none of them a virus.
Why the classic kind has nowhere to go
A virus, in the original sense, is a program that copies itself into other programs. To do that it needs somewhere to write a copy and permission to run it. Apple’s own platform security documentation describes three mechanisms that remove both, and it is worth reading them as specifics rather than as reassurance.
Every third-party app is sealed off. In Apple’s words: “All third-party apps are sandboxed. Sandboxing is designed to prevent apps from gathering or modifying information stored by other apps or from making changes to the device.” Each app gets “a unique home directory for its files, which is randomly assigned when the app is installed”, and reaches anything outside it only through services iOS chooses to provide.
Permissions cannot be forged. Access to your information and to features such as iCloud is governed by declared entitlements, and because “entitlements are digitally signed, they can’t be changed”. Apple adds that ordinary APIs “don’t allow apps to escalate their own privileges to modify other apps” or the operating system.
And there is nowhere to write. The plainest sentence in the document is also the most consequential: “the entire operating system partition is mounted as read-only.” Apple notes too that “unnecessary tools, such as remote login services, aren’t included in the system software”. Two further protections sit underneath — address space layout randomisation, which scrambles where code sits in memory, and ARM’s Execute Never feature, which marks memory pages as non-executable.
None of this makes an iPhone unbreakable, and Apple does not claim it does. What it does is make self-spreading software the wrong tool: the rare real attacks on iPhones are aimed at individuals at great expense, which is a different problem with a different answer.
| What was checked | How many | Of those, stopped |
|---|---|---|
| App submissions reviewed | more than 9.1 million | over 2 million rejected — 1.2 million new apps, nearly 800,000 updates |
| Submissions with hidden or undocumented features | — | over 22,000 rejected |
| Apps that changed after approval | — | nearly 59,000 removed for “bait-and-switch” |
| Apps outside the App Store, on pirate storefronts | — | 28,000 blocked, described as including malware |
| Attempts to install apps from outside the store | in one month | 2.9 million prevented |
The second wall, with numbers on it
The other reason is the store. “Apple reviews every app” is repeated everywhere and is almost never given a size, which makes it impossible to judge. Apple publishes the size once a year, and the report covering 2025 came out on 20 May 2026.
App Review “evaluated more than 9.1 million app submissions” and “rejected over 2 million app submissions — including over 1.2 million new apps and nearly 800,000 app updates”. Within that: over 22,000 rejected “for containing hidden or undocumented features”, and over 443,000 “for privacy violations”.
The most interesting figure is not about submissions at all. Apple describes apps “that were initially approved as standard games or utilities, such as a puzzle or calculator app, that then modified their software post-review with the intent of financial fraud”, and says that “in 2025, the team removed nearly 59,000 apps” for doing it. That is review failing and being caught afterwards, published by the company that runs the review — and it is the honest reason to keep an eye on what is installed even on a phone that only uses the official store.
Outside the store the numbers get blunter. Apple says it “detected and blocked 28,000 illegitimate apps on pirate storefronts, which include malware”, and that “in the last month alone” it prevented “2.9 million attempts to install or launch apps distributed illicitly outside the App Store or approved alternative app marketplaces”.
One caveat belongs with all of it. These are Apple’s figures about Apple’s own work, and nobody audits them. They are quoted here because a number with a date attached can at least be argued with, which an adjective cannot — not because the source is neutral.
What does happen, which is four things and none of them a virus
A web page. By far the most common. A page displays a countdown, a fake scan or a warning that several viruses have been found. It is a website: it cannot see the phone it is drawn on, it has no access to your photos or messages, and it goes away when Safari’s website data does.
A configuration profile. The only ordinary mechanism by which something outside the App Store changes how your iPhone behaves — it can set a VPN, a proxy or restrictions, and Apple’s personal safety guidance warns that such tools “may allow access to data or location information on the device”. It arrives by being tapped through, usually on a page that was offering something else. That is the one worth checking, and how to remove virus from iPhone is where the check and its two warnings are set out step by step.
Your Apple Account password. Not an infection at all. Someone signing in as you sees your photos, messages and location without anything being installed anywhere, which is precisely why no scanner could ever find it. The signs are account-shaped rather than device-shaped: messages you did not send, sign-in alerts, changed settings.
And, rarely, a targeted attack. Mercenary spyware exists, and Apple runs a notification system for it. In Apple’s words these are “high-confidence alerts that a user has been individually targeted”, and “the vast majority of users will never be targeted by such attacks”. If it happens you are told, on the Lock Screen and in Settings, by email, and by a banner on your account page — not by an app you installed.
The awkward consequence: no app can check any of this for you
The sandbox is the answer to the question and also the reason the obvious next step does not work. An app that offers to scan your iPhone is itself sandboxed, so it cannot read Safari’s data, list your configuration profiles or examine other apps. There is no exception for security software.
The clearest statement of what follows comes from a body with nothing to sell. The UK’s National Cyber Security Centre, in its device security guidance, writes that “this means you should not need to use AV products on platforms like Chrome OS, Android and iOS in their default configuration” — because devices that “can only run software that is delivered through a public app store which monitors for malicious code” are devices where antivirus “offers very limited value”.
The apps sold for this purpose are not frauds; they are usually a web filter, a VPN or a data-breach lookup, all of which are real things. They are just not a scanner, because a scanner is not something iOS permits anything to be.
So: can an iPhone get a virus?
The short answers, each tied to the part of the page that shows the working.
Where the answers in the search results come from, and why this page is built differently. The question attracts a lot of writing by companies that sell security software, and the useful test is not whether they are trustworthy but whether a claim can be checked. “iPhones are very secure” cannot be. “The entire operating system partition is mounted as read-only” can be, because it appears in Apple’s platform security documentation and says something specific about what is possible. Every load-bearing sentence above is of the second kind, and where a source has an interest in the answer — Apple counting Apple’s own work — the page says so at the point it matters.
If something is wrong right now, the order matters more than the theory. Clear Safari’s website data, look at the profile list, remove apps you do not know — how to remove virus from iPhone is the same three checks with Apple’s exact wording and its two warnings. If the phone is simply behaving badly, running hot, draining its battery and restarting itself are the three symptoms blamed on viruses most often and caused by them least.
Where to start
Three ways in.
- “Why can’t a virus spread here?”
- The three walls — why rare
- “What does get through, then?”
- Four things, and their sizes — what does happen
- “Which scanner should I install?”
- Why none of them can work — no scanner
If something is wrong now
This page explains what is possible. These are the ones with the steps in them.
The problems mistaken for this one
Most iPhones brought in for a virus do not have one. These are what they usually have instead.
Questions people also ask
How do I know if my iPhone has a virus?
You look in three places rather than run a scan: Safari’s website data, the list at Settings, General, VPN & Device Management, and the apps on your Home Screen. Apple’s wording for a clean profile list is useful — if none are shown, none are installed.
Can Apple run a virus scan on an iPhone?
No, and neither can anyone else. Every app is sealed inside its own sandbox, so nothing running on the phone can inspect the rest of the phone. What Apple does instead is watch for targeted attacks centrally and notify the person affected.
Do iPhones need antivirus software?
The National Cyber Security Centre’s guidance is that you “should not need to use AV products” on iOS in its default configuration, because a device that can only install from a monitored app store gains very little from one.
Can an iPhone get a virus from a website?
Not by loading a page. What a page can do is persuade you to install a configuration profile, which is a real change to the phone and the one thing worth checking after something strange in the browser.
Are iPhones safer than Android phones?
Both restrict what can be installed and both review their stores, so the honest comparison is about defaults rather than about which is better. The practical difference is that Android permits installing apps from outside its store, and iOS mostly does not.
Why does my iPhone say it has a virus?
Because a web page said so. A page cannot examine the device it is displayed on, so any page claiming to have detected an infection is guessing in order to sell something or to collect a tap.
Not covered here. It does not rank security apps, because on iOS in its default configuration the NCSC’s guidance is that none is needed — and ranking them would mean paying for them and measuring something they are not doing.
It does not cover jailbroken phones, where the read-only system partition and the store review have both been removed on purpose, and none of the reasoning above applies.
And it does not cover what to change once an account rather than a device has been taken. That is what to do after a data breach, and it starts from a different machine. What holds instead is simple: the three runtime protections are quoted from Apple’s platform security documentation rather than summarised from a vendor blog, every App Store figure carries the year and the report it comes from and is labelled as Apple counting its own work, the sentence on antivirus is the National Cyber Security Centre’s in full, and nothing here is attributed to the Apple user forum that the search results treat as Apple.
Sources
- Apple Platform Security — Security of runtime process in iOS, iPadOS, and visionOS: that all third-party apps are sandboxed and cannot gather or modify other apps’ data, that each app gets a randomly assigned home directory, that the entire operating system partition is mounted read-only, that digitally signed entitlements cannot be changed and APIs do not allow privilege escalation, plus address space layout randomisation and ARM’s Execute Never feature — support.apple.com, read 9 September 2026.
- Apple Newsroom, 20 May 2026 — The App Store stopped over $2.2 billion in fraudulent transactions in 2025: more than 9.1 million submissions reviewed and over 2 million rejected, over 22,000 rejected for hidden or undocumented features, over 443,000 for privacy violations, nearly 59,000 apps removed for changing their software after review, 28,000 illegitimate apps blocked on pirate storefronts, and 2.9 million attempts in one month to install apps from outside the store — www.apple.com, read 9 September 2026.
- Apple Support — About Apple threat notifications and protecting against mercenary spyware: that these are high-confidence alerts about individually targeted attacks and should be taken very seriously, that the vast majority of users will never be targeted, and the three channels through which such a notification arrives — support.apple.com, read 9 September 2026.
- Apple Personal Safety User Guide — Review and delete configuration profiles: that configuration profiles and mobile device management tools may allow access to data or location information on the device, and where an installed profile is listed and removed — support.apple.com, read 9 September 2026.
- National Cyber Security Centre — Antivirus and other security software, Device security guidance: that you should not need to use antivirus products on Chrome OS, Android and iOS in their default configuration, and the reasoning that a device restricted to a monitored public app store gains very limited value from one — www.ncsc.gov.uk, read 9 September 2026.
Written by Alberto Gulotta
Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.
Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.
Written on 9 September 2026.
Independence and limits
No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.
This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.