In-App Purchase Vulnerability to Be Fixed in iOS 6; Apple Offers Best Practices to Developers
As noticed by 9to5Mac, Apple has offered developers a series of best practices to prevent the In-App Purchase vulnerability, as well as promising a full fix in iOS 6. The advisement was sent to developers in an email today.
CNET was issued this statement by Apple:
"We recommend developers follow best practices at developer.apple.com to help ensure they are not vulnerable to fraudulent In-App purchases," Apple spokesperson Tom Neumayr told CNET. "This will also be addressed with iOS 6."
Apple issued this note to developers on the iOS Developer webpage, along with a series of suggestions to help verify that in-app purchases are legitimate:
A vulnerability has been discovered in iOS 5.1 and earlier related to validating in-app purchase receipts by connecting to the App Store server directly from an iOS device. An attacker can alter the DNS table to redirect these requests to a server controlled by the attacker. Using a certificate authority controlled by the attacker and installed on the device by the user, the attacker can issue a SSL certificate that fraudulently identifies the attacker’s server as an App Store server. When this fraudulent server is asked to validate an invalid receipt, it responds as if the receipt were valid.
News of the in-app purchase hack broke a week ago, and Apple has made several attempts to prevent users using the hack. It allows users to avoid paying for in-app purchases by using a third-party server as a "man-in-the-middle" attack. Apple now includes the UDID identifier in in-app purchase receipts in an attempt to increase the security of purchases.
Popular Stories
Apple today released firmware updates for both AirPods 4 models (version number 7B20) and the AirPods Pro 2 with both Lightning and USB-C charging cases (version number 7B21). All of these AirPods models were previously on firmware version 7B19.
It is not immediately clear what new features or changes are included in firmware versions 7B20 and 7B21, but we will update this story if we find...
In its announcement video for the new Mac mini last month, Apple teased an "upcoming" version of Final Cut Pro for the Mac. Apple will likely announce the update during the annual Final Cut Pro Creative Summit, which begins this Wednesday. The conference is held in association with Apple, and attendees will be visiting Apple Park on the first day.
Apple already teased four new features...
Next year's iPhone 17 "Air" model may not be as thin as Apple planned, according to a rumor originating in Korea.
According to the news aggregator account "yeux1122" on Naver, citing industry sources, Apple has run into problems making the new iPhone 17 model sufficiently thin. The device's reduced thickness is apparently dependent on manufacturing a battery with a thinner substrate, but...
Black Friday is getting closer, and prices on MacBook Pro, MacBook Air, iMac, and Mac mini computers have started to drop as the shopping holiday nears. These deals include the latest models of the M4 MacBook Pro and iMac.
Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site...
Black Friday sales are continuing today with Best Buy kicking off early Black Friday deals that will last for the next few days. Similar to other retailers, Best Buy's early Black Friday event includes sitewide savings on Apple products, headphones, TVs, monitors, video games, and more.
Note: MacRumors is an affiliate partner with Best Buy. When you click a link and make a purchase, we may...
Last week, we reported on a new feature in the Find My app on the iOS 18.2 beta that allows you to temporarily share an AirTag's location with a trusted person, and soon with airlines. Apple today announced the feature, providing more details.
Apple said more than 15 airlines will offer the feature "in the coming months," including Delta, United, Air Canada, British Airways, Virgin Atlantic, ...
Apple seeded the third betas of iOS 18.2 and iPadOS 18.2 to developers for testing today. While the third betas of each update are minor relative to the first two betas, there are still a handful of changes across the Photos app, TV app, and more.
A corresponding iOS 18.2 public beta with these changes will likely be released later this week, and Apple previously confirmed that the software...
It has been nearly two and a half years since Apple first previewed next-generation CarPlay at WWDC 2022, and it has still yet to become available in any vehicles. Fortunately, though, Apple continues to work on the software system.
Within the code for the third beta of iOS 18.2 seeded to developers today, there are redesigned "Climate" and "Media" app icons for next-generation CarPlay,...