Overview
- Apple’s revamped web App Store introduced new platform, category, and search pages before the code exposure was noticed.
- Sourcemaps were mistakenly left enabled in production, allowing GitHub user rxliuli to extract the complete frontend using a Chrome extension.
- The archived repository includes Svelte and TypeScript source, UI components, state logic, API integrations, and routing configuration.
- Reporters observed that Apple’s developers have now disabled sourcemaps on the live site.
- The GitHub archive remained accessible at the time of reporting, with coverage noting minimal immediate security or privacy risk and no public comment from Apple.