
iOS 27 ships, privacy manifests become a hard submission blocker, Flutter adapts, and AppsOnAir launches Link Validator and Push Notifications Beta.
Overview
September is Apple's month. iOS 27 released alongside new iPhone hardware, Xcode 27 went final, and App Store submission requirements changed the moment the OS dropped. On Android, the API 36 deadline is six weeks away — and predictive back gesture support is the part most teams skipped. Flutter 3.47 (released August 12, 2026) ships Widget Previewer stable, SwiftPM Add-to-app support, and built-in Kotlin Gradle plugins — with a patch for iOS 27 day-0 compatibility on Xcode 27. React Native 0.87 is stable; Expo SDK 58 ships with iOS 27 support. Here's the full breakdown.
iOS 27
New Permission APIs
iOS 27 introduces three new permission categories:
- Location precision: users grant exact vs. approximate access per use, not per session.
- Contacts field-level access: apps must request individual contact fields (name, phone, email) rather than full address book access via CNContactStore.
- On-device AI declarations: - apps using CoreML or Apple Intelligence APIs must declare intent via a new NSAppleIntelligenceUsageDescription key in Info.plist.
- Update permission_handler, contacts_service, and any location plugin before submitting to the App Store.
- Source: Apple Developer News & Releases
What Developers Need to Do
The new permission APIs require action at three layers:
App level: Add new NSUsageDescription keys to Info.plist for each new permission category your app uses. For location precision, the existing NSLocationWhenInUseUsageDescription key remains, but users now see a precision selector at grant time. For field-level contacts access, you must call the updated CNContactFetchRequest API that accepts specific field keys.
Plugin level: iOS 27 permission changes require plugin updates. Check pub.dev (Flutter) or npm (React Native) for iOS 27-compatible versions before upgrading Xcode. Submitting with an outdated plugin that calls deprecated contact or location APIs will surface validation errors in Xcode 27's archive process.
Privacy manifest level: If your app uses the new CoreML or Apple Intelligence APIs, your `PrivacyInfo.xcprivacy` must include the relevant declared reason. An app-level manifest missing an API declaration will be flagged during App Store Connect validation.
Source: iOS & iPadOS Release Notes - Apple Developer Documentation
Xcode 27 Final - Swift 6 Strict Concurrency, iOS 16 Minimum
Xcode 27 ships Swift 6 strict concurrency enabled by default for all new targets. Mixed Objective-C/Swift plugin bridges will surface warnings-as-errors in plugin Swift files. The minimum iOS deployment target for new Xcode 27 projects is iOS 16.
E.g: For flutter
flutter upgrade # ensure Flutter 3.47+
pod repo update
flutter build ios --releaseOpen the Xcode build log and resolve any Swift concurrency errors before archiving for App Store submission.
Source:
App Store: Social Media Age Rating — Now Required
The age rating questionnaire change flagged in July is now enforced. All new submissions must declare whether the app has social media capabilities — defined as the ability to redistribute, amplify, or interact with user-generated content via a social feed. Apps that qualify display a Social Media content descriptor on their product page. Missing responses block submission.
Source: App Store Review Guidelines 1.3
Privacy Manifests: Now a Hard Submission Blocker
App Store Review is actively rejecting builds where PrivacyInfo.xcprivacy is missing, incomplete, or inconsistent with actual API usage. This is no longer advisory.
Required for every app and every plugin that accesses:
- File system
- NSUserDefaults / UserDefaults
- CoreLocation
- Contacts
- Camera / microphone
- On-device ML / CoreML
Checklist:
- Verify each plugin has shipped PrivacyInfo.xcprivacy on GitHub. Update to the latest version.
- Add your app-level manifest at ios/Runner/PrivacyInfo.xcprivacy.
- Archive in Xcode 27 and run App Store Connect validation before submitting - it surfaces manifest issues before review.
Source: Privacy Manifest Files - Apple Developer Documentation
Android
Predictive Back Gesture - Implementation Required
Targeting API 36 is not enough. On Android 16 devices, the system renders an animated preview of the destination screen on back swipe. Apps that intercept back events via the deprecated onBackPressed() without adopting OnBackPressedCallback show broken or missing animations.
Flutter-specific: WillPopScope is the primary cause of broken predictive back on Android 16 devices. Migrate to PopScope with `canPop` and `onPopInvokedWithResult`.
// Before
WillPopScope(
onWillPop: () async => false,
child: ...,
)
// After
PopScope(
canPop: false,
onPopInvokedWithResult: (didPop, result) { ... },
child: ...,
)Test on an Android 16 emulator with predictive back enabled in developer options (Settings → Developer options → Predictive back animations).
Source:
Android Privacy Sandbox - Fully Active
Android 16's Privacy Sandbox APIs are live: Topics API, Protected Audience API and Attribution Reporting API replace ad_id-based cross-app tracking. Ad network SDKs that have not been updated to support these APIs will produce attribution gaps as Android 16 device adoption grows.
Source: Android Privacy Sandbox
Google Play Data Safety — Now Verified, Not Self-Reported
Google Play has moved Data Safety section declarations from self-reported to actively verified. Play Console will flag discrepancies between declared data practices and what bundled SDKs actually access. Mismatches result in a warning badge on the Play Store listing - visible to users.
Audit your third-party SDK list and confirm each publishes a Data Safety disclosure consistent with your app's declaration.
Source: Data Safety section - Play Console Help
Flutter & Dart
iOS 18: Two Years Later — What It Permanently Changed
iOS 18 (September 2024) drove three structural shifts that are now baseline expectations:
- Privacy manifests became mandatory: Apple's PrivacyInfo.xcprivacy requirement — enforced from May 2024, means every plugin touching device APIs must ship an explicit manifest. Major plugins (firebase_core, url_launcher, image_picker, path_provider, shared_preferences) now include them. A plugin without one is a submission risk.
- Impeller replaced Skia as the default iOS renderer: Flutter 3.22 made Impeller (Metal-backed) the default. iOS 18's Metal improvements benefited Impeller frame pacing and most launch-era rendering edge cases are resolved. Skia is no longer the recommended fallback.
- Swift Package Manager displaced CocoaPods: Flutter started experimental SPM support in 3.22 alongside Xcode 16. It matured through 3.24–3.29. Flutter 3.44 made SPM the default, CocoaPods is now in maintenance mode.
Source:
Flutter 3.47 - Widget Previewer Stable, SwiftPM Add-to-App, Kotlin Gradle Built-In
Flutter 3.47 was released August 12, 2026, The headline features:
- Widget Previewer - Stable: Graduated from experimental. Local build caching and real-time preview search/filtering are now available to all Flutter developers without any experimental flag.
- Swift Package Manager expanded to Add-to-app: Previously SPM support applied only to standalone Flutter apps. Flutter 3.47 extends SwiftPM integration to Add-to-app workflows, closing a major gap for teams embedding Flutter in existing native apps.
- Built-in Kotlin Gradle plugins: A new migration guide covers moving away from custom Kotlin Gradle plugin configurations to Flutter's built-in Kotlin support — reducing build configuration maintenance overhead.
- WebAssembly improvements: --source-maps flag support for web builds, plus expanded troubleshooting documentation for Wasm compilation errors.
- Platform-specific assets: Assets can now be declared per-target platform in pubspec.yaml, eliminating the need for manual asset filtering in build scripts.
- For iOS 27 day-0 support: Flutter 3.47.x patch releases ship alongside iOS 27 to ensure Xcode 27 and iOS 27 SDK compatibility. Ensure you are on the latest Flutter 3.47 stable patch before submitting iOS 27 builds.
Key Migration Steps:
# Step 1: Upgrade Flutter
flutter upgrade
flutter --version # Verify: Flutter 3.47.x · Dart 3.13.x
# Step 2: Update minimum iOS target in Podfile
platform :ios, '16.0'
# Step 3: Run Dart analysis -- address any new exhaustive switch errors
dart analyze
# Step 4: Build release and review Xcode 27 build log
flutter build ios --releaseDart 3.13 sealed class exhaustiveness: If your codebase uses sealed classes with switch expressions or statements, run `dart analyze` after upgrading. Non-exhaustive switches on sealed types now produce errors where they previously produced warnings. Add the missing case arms or use a wildcard (`_`) if the unmatched cases are intentional dead code.
CocoaPods Sunset - Official Timeline
Teams with private podspecs, custom post_install hooks, or local pod path references should start migrating now. The SPM migration is not a refactor - each local plugin must be converted to an SPM local package. Expect 2–4 weeks for projects with 5+ private plugins.
Source:
- Flutter Swift Package Manager - for plugin authors
- Flutter Swift Package Manager - for app developers
- Flutter GitHub - SPM tracking
React Native 0.87 Stable & Expo SDK 58
React Native 0.87 shipped stable in August. The RC-to-stable transition was clean — no new breaking changes from RC.2 (covered last month). The September callout: the legacy bridge architecture will not receive iOS 27 compatibility patches. Teams on RN 0.73 or earlier cannot ship iOS 27-targeted builds without migrating to the New Architecture first.
Expo SDK 58 ships with full iOS 27 and Xcode 27 support, drops iOS 15 and below
Migration
# Expo managed workflow
npx expo upgrade
# Bare / community CLI
npx @react-native-community/upgrade-helperTarget November 2026 as your migration deadline. iOS 27 device adoption will exceed 50% by then - bridge-mode builds will be a user-visible problem.
Source:
New Architecture Migration - What Actually Changes
Moving from the legacy bridge to the New Architecture involves two key components:
- TurboModules: replace the bridge for native module calls. The bridge converted all JS↔Native calls to JSON serialization - TurboModules use JSI (JavaScript Interface) for synchronous, direct function calls with C++ type safety. The performance difference is measurable: bridge-mode apps show 15–40ms overhead on native calls that TurboModules handle in microseconds.
- Fabric renderer: replaces the shadow thread for UI updates. Fabric synchronizes the JS and native UI trees directly, enabling concurrent rendering and eliminating the frame-delay artifacts common in complex scroll views and animated transitions under the bridge.
Breaking changes teams hit most:
- Third-party libraries without TurboModule support will not compile under New Architecture. Check the React Native Directory for each library's New Architecture status before migrating.
- UIManager direct calls no longer work - replaced with `useAnimatedRef` and the new `measure` API from Reanimated 3+.
- Native modules written in Objective-C without JSI bindings need to be migrated — this is the step that takes the most time for teams with custom native modules.
Source:
AI in Mobile Development
AI is moving from a developer productivity tool into the mobile runtime itself. In 2026, mobile teams are using AI across the entire development lifecycle — from generating code and tests to debugging production crashes and adding on-device intelligence to apps.
AI is becoming part of the mobile development workflow — from writing code and generating tests to debugging builds and analyzing production issues.
Where AI Is Making an Impact
- AI-assisted development — Generate boilerplate, refactor code, write tests, and assist with Flutter, Android, iOS, and React Native migrations.
- AI-powered testing — AI can understand screens and user flows, making mobile UI testing more resilient than traditional selector-based automation.
- On-device AI — Local AI enables faster, offline, and more privacy-focused experiences for tasks such as summarization, translation, image understanding, and personalization.
- AI release engineering — Build logs, crash reports, CI failures, and dependency changes can be analyzed together to identify release issues faster.
What developers should do: Start using AI where it reduces repetitive work, but keep human review for production code, security, performance, and release decisions.
What to Prioritize
Not all of this is equal urgency. Here is a triage order for September 2026:
From AppsOnAir
Push Notification Service - Beta
AppsOnAir Push Notifications is now in beta: a unified push delivery layer across mobile and web platforms. Configure notification templates, define targeting segments, schedule delivery, and track open rates and delivery analytics - all from the AppsOnAir portal. Setup and credential configuration is required once; ongoing send management happens entirely through the portal.
If you are already using AppsOnAir for OTA distribution or app management, push is one toggle in app settings.
Join the beta: AppsOnAir Push Notifications
Link Validator - Now Available
Test any deep link URL against iOS and Android resolution rules without a build or a device. The validator checks:
- URL scheme registration
- apple-app-site-association (AASA) file health and path pattern matching
- assetlinks.json health
- End-to-end resolution across iOS Universal Links and Android App Links rules
Broken deep links in OTA update flows, push notification tap destinations, and campaign URLs are invisible on your end — they surface as user complaints. The Link Validator finds them before they ship.
Try it: Appsonair link-validator
Summary
Conclusion
September 2026 reinforces a clear direction for mobile development: platforms are becoming more privacy-focused, tooling is becoming more automated, and AI is becoming part of the development lifecycle.
For mobile teams, the priority is to stay current with iOS 27 and Android 16, modernize Flutter and React Native projects, audit privacy requirements, and start using AI where it can shorten the path from development → testing → release.
The teams that prepare now will spend less time fixing platform surprises and more time shipping reliable mobile experiences in 2027.
Happy coding! 🚀
.png)


