Intelligence View
Apple Sued Over Continuity Camera as Camo App Maker Alleges Patent Theft
Apple faces a lawsuit in a New Jersey federal court over its Continuity Camera feature. Reincubate, the London-based company behind the Camo app, claims Apple copied its patented technology and built it into iOS to push users toward…
What the lawsuit alleges
Reincubate released Camo in 2020. The app lets users turn iPhones and Android phones into webcams for desktop video calls. Two years later, Apple launched Continuity Camera in iOS 16. The feature allows iPhones to act as wireless webcams for nearby Macs signed into the same Apple Account.
According to the complaint, Apple did not just build a similar feature. Reincubate argues that Apple encouraged the company to develop and promote Camo for iOS, then used shared information to design Continuity Camera.
“Apple actively cultivated a relationship of trust with Reincubate, induced the company to share technical details, beta builds, and market data, and leveraged that privileged access to inform its own development of Continuity Camera.”
Reincubate describes Apple’s behavior as “Sherlocking,” a term developers use when Apple adds system features that replicate third-party apps and weaken their businesses.
“Rather than competing with us, Apple deployed a series of obstacles to tilt the playing field, infringed our IP, and did so in service of preventing competition from rival platforms,” said Reincubate CEO Aidan Fitzpatrick.
Apple’s response and antitrust claims
Apple rejected the allegations and said it developed the camera features internally.
“Apple competes fairly while respecting the intellectual property rights of others, and these camera features were developed internally by Apple engineers.”
Beyond patent infringement, the lawsuit includes antitrust claims. Reincubate argues that Apple locks users into its ecosystem and makes it harder for them to switch to competing platforms. The company seeks monetary damages and court orders to stop what it calls Apple’s anti-competitive conduct.
The case adds to ongoing scrutiny of how Apple integrates new features into iOS and macOS, especially when those features overlap with independent developer apps.
1. Sofort-Triage & Abwehrmaßnahmen
SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - Apple Sued Over Continuity Camera as Camo App Maker Alleges Patent Theft
id: 4cd9e369-9aab-460d-a1b2-df6c34c011ac
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-25"
description = "YARA Signature for "
strings:
$str = "Apple Sued Over Continuity Cam" ascii wide
condition:
any of them
}index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Apple Sued Over Continuity Camera as Cam")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - countmessage: "*Apple Sued Over Continuity Camera as Cam*"CommonSecurityLog
| where Message has "Apple Sued Over Continuity Camera as Cam"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc2. Cyber Threat Intelligence & Forensik
MITRE ATT&CK Matrix Navigator 14 Taktiken
tsecurity.de Cognitive Threat RAG
Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Apple Sued Over Continuity Camera as Cam.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.