On September 29, 2026 at 00:41 UTC, which was 17:41 on September 28 in California, iOS apps with Google Analytics for Firebase started crashing on launch. The developers hit by it had shipped nothing. A Firebase server began returning an experiment payload the SDK couldn't parse, and the parse threw an exception that killed the app. Firebase maintainer ncooke3 wrote on issue 16728 that the issue was resolved at 23:52 US/PDT on September 28, about six hours after the first crash. A Hacker News thread about the crashes reached the front page on September 30.
The crash
The first report on GitHub came from a team that saw 56 crashes across 56 users within 18 minutes, spread over four released builds. The exception reads:
NSInvalidArgumentException
*** -[__NSDictionaryM setObject:forKeyedSubscript:]: key cannot be nil
The stack trace shows where it happened:
-[GULMutableDictionary dictionary]
-[APMEExperiment copyWithZone:]
-[APMESnapshot initWithSDKName:experiments:]
-[APMESnapshot initWithProtobuf:]
-[APMETaskManager experimentSnapshotsFromExperimentResponse:]
-[APMETaskManager handleFetchingExperimentsResponse:data:error:]
__35-[APMETaskManager fetchExperiments]_block_invoke
Read it from the bottom. The Analytics task manager fetched experiments, built snapshots from the protobuf response, and copied each experiment into a dictionary. One experiment carried a nil key. NSMutableDictionary throws on a nil key, and nothing above it caught the exception. The GUL prefix belongs to GoogleUtilities, the shared library under the Firebase SDKs.
The reporter ran Firebase 12.14.0, installed through Swift Package Manager and built with Xcode 26.5.
Sep 28, 17:41 PDT
Firebase begins serving the malformed sdk-exp payload (00:41 UTC on Sep 29).Sep 28, 23:52 PDT
Firebase reports the issue resolved.Sep 29
Issue 16728 collects reports. Firebase ships GoogleUtilities 8.1.4.
The fix, and the part you own
Google fixed the payload, and the maintainer wrote that "an SDK update is not required to resolve this issue." Your app needed no release. The crash reports kept arriving after the fix, though. Crashes from the six-hour window often get reported the next time a user starts the app, so dashboards kept climbing after the server stopped sending bad data. The maintainer asked anyone who sees crashes after the resolution time to open a separate issue.
Google also released GoogleUtilities 8.1.4 to make the SDK more resilient to bad server data, so the next malformed payload has a better chance of failing without taking the process down. That update is on you. Check what your project resolves today:
# CocoaPods
grep -n "GoogleUtilities" Podfile.lock
pod update GoogleUtilities
# Swift Package Manager: find the resolved version
grep -n -A4 '"googleutilities"' \
*.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved
On SPM, use File, Packages, Update to Latest Package Versions in Xcode, or bump the package's minimum version, then commit the new Package.resolved.
Remote payloads in your crash budget
You can review your own code, pin your dependencies and run your tests, and a server you don't control can still crash your app on users' phones. Analytics, remote config, feature flags and A/B testing SDKs fetch data at launch and parse it in your process. Two habits limit the damage when one of them sends garbage.
- Initialize third-party SDKs after your first screen renders where the SDK allows it, so a crash in a background fetch hits a running app instead of a launch loop.
- Alert on crash-free sessions dropping across all builds at once. A spike spread over several old versions points at a server, and you can stop debugging your last commit.
The reporter's four builds all crashing at the same minute is the signal to look for. Your code was different in each of those builds, and the one thing they shared was the payload.
This week
- Update GoogleUtilities to 8.1.4 or later in each iOS app that uses Firebase, and ship it with your next release.
- Annotate your crash dashboard for September 28 and 29, so your team doesn't spend a sprint chasing that spike.
If your crash-free rate for those two days dragged a release gate below its threshold, exclude the window and re-run the gate.
Volodymyr Chornous

