Apple investigating App Store bug that gave free in-app purchases

Apple is investigating a bug uncovered by a Russian hacker that allowed customers to get free in-app purchases. The hacker, who identifies himself as ZonD80, posted a YouTube video showing how to get around paying for features in the apps featured in Apple’s store last week. He has since started a Web site asking for donations to support his work.

Apple said that it is looking into the situation. “The security of the app store is incredibly important to us and the developer community. We take reports of fraudulent activity very seriously and we are investigating,” said Apple spokeswoman Natalie Harrison.

Multimedia

WASHINGTON, DC. MAY 21, 2013:   3-D Display with Haptic Touch Screen can be applied to medical and robotics, at Microsoft TechFair in Washington, DC on May 21, 2013. ( Photo by Jeffrey MacMillan )

Microsoft showcases new technologies in D.C.

The software giant displayed some of its most cutting-edge innovations at a fair.

More tech stories

All about Waze: Why Google or Facebook might want it

All about Waze: Why Google or Facebook might want  it

As more firms add social data to their maps, the community-based navigation app is looking attractive.

12 technologies that will shape the future

12 technologies that will shape the future

A McKinsey Global Institute study shows how innovations that get the most hype aren't necessarily the ones that will make the biggest difference economically.

Small businesses: You are not immune to a mobile hack

Small businesses: You are not immune to a mobile hack

Small firms becoming more frequent victims of mobile cyber attacks due to their position as “gateways” to larger firms’ or consumer data.

According to a report from Information Week, the hacker said that he has received a takedown notice from Apple asking him to take down his Web site.

The report said that the hack works on iOS versions 3.0 to the as-yet-unreleased 6.0, though it doesn't work on all mobile applications. Developers do have the option to verify purchases, the report said.

The hack could seriously hurt app developers, MacWorld noted, who have largely depended on Apple for security and to process payments — which can help to justify the 30 percent cut Apple takes from developers.

MacWorld’s Marco Tabini, also a developer, said that Apple has done a good job of patching up rocky situations with developers over this sort of thing in the past, and that he expects this won’t damage that relationship too much. He did note that more developers should take the time to set up their own validation systems for in-app payments, but also said that Apple has to give smaller developers the confidence that they don’t have to be cryptology experts to feel safe on the App Store.

Related stories:

Apple’s Mountain Lion may be out July 25, report says

Apple developing smaller iPad, will cost ‘significantly less’ than $499, report says

Apple fixes App Store bug

Loading...

Comments

Add your comment
 
Read what others are saying About Badges