On November 4, 2025, a significant security lapse occurred when Apple launched its revamped App Store website, inadvertently enabling JavaScript sourcemaps in production. This oversight allowed individuals to download Apple's entire front-end codebase using a Chrome extension, which they subsequently archived on GitHub for educational purposes.
This incident highlights a broader issue, as similar vulnerabilities were detected in 70% of various organizations utilizing Escape DAST for scanning external assets. Apple's situation has brought attention to a common security flaw that many companies face.
To address such vulnerabilities, experts recommend automating the discovery of leaked sourcemaps to ensure that exposed files do not go unnoticed. This proactive approach can help prevent future incidents similar to what Apple experienced.