iOS 9 code vulnerability lets hackers steal thousands of dollars worth of in-app purchases
It’s not a trend that gamers are especially ecstatic about, but in-app purchases (IAP) have become a major element of mobile gaming. It’s how many of the biggest games on the App Store stay afloat, but earlier this week, the developers at DigiDNA discovered a coding flaw that could allow hackers to steal thousands of dollars worth of IAP from popular games.
“Yesterday morning, while testing iMazing 1.3’s new app backup/restore feature, we realised that quite a few popular apps contain severe weaknesses in their in-app purchase (IAP) handling code, resulting in vulnerabilities which can easily be exploited to manipulate IAPs,” says the DigiDNA team.
After tweaking Angry Birds 2, the developers were able to start a new game with 999,999,999 gems, which serve as the premium currency in Rovio’s latest game. It would cost a user $10,000 to get that many gems legitimately.