Bug in Apple Store Allowed more than 500 iPhones For Just 0.03 USD

A Taiwanese IT engineer named Chang Chi-yuan uncovered a bug in the Apple’s payment system that allowed him to buy more than 500 iPhones for a Taiwanese dollar which is equivalent to 0.03 USD.

He posted screenshots on Facebook indicating that he successfully paid a Taiwanese dollar for 500 iPhone 8 Plus 256 GB and for two Phone XS Max 512 GB which worth 540,354.47 USD.

The Apple iPhone 8 Plus was launched in September 2017, it is powered by the hexa-core processor and comes with a display resolution of 1080 pixels by 1920 pixels.

Anyhow once the transaction was accepted Chang Chi-yuan managed to cancel the purchase, Change already purchased iPhones cheaper than the original cost in 2016, he says the bug is similar to the one and it was not yet fixed. reported Taiwannews.

Chang gets attention in 2013 when he deleted a series of Facebook posts by Facebook founder Mark Zuckerberg to highlight a bug he found, after being ignored by tech support.

Few months before a new vulnerability “iOS Trustjacking” identified discovered in the iOS device that allows an attacker to control the Vulnerable device remotely and perform various malicious activities. Another researcher proved that the iPhones and iPads4/6 digits PIN’s can be bypassed with a brute force attack.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

NVIDIA Patch Multiple GPU Display Driver for Windows & Linux

NVIDIA has issued essential security updates for its GPU Display Driver, addressing multiple vulnerabilities affecting…

2 hours ago

GitLab Patches HTML Injection Flaw Leads to XSS Attacks

GitLab has announced the release of critical security updates for its Community Edition (CE) and…

1 day ago

Xerox Printers Vulnerable to Remote Code Execution Attacks

Multiple Xerox printer models, including EC80xx, AltaLink, VersaLink, and WorkCentre, have been identified as vulnerable…

1 day ago

Cisco ASA Devices Vulnerable to SSH Remote Command Injection Flaw

Cisco has issued a critical security advisory regarding a vulnerability in its Adaptive Security Appliance…

1 day ago

Google Patches Multiple Chrome Security Vulnerabilities

Google has released several security patches for its Chrome browser, addressing critical vulnerabilities that malicious…

1 day ago

Grayscale Investments Data Breach Exposes 693K User Records Reportedly Affected

Grayscale Investments, a prominent crypto asset manager, has reportedly suffered a data breach affecting 693,635…

2 days ago