.png)
50+ planted vulnerabilities. Your job: find them.
BugBazaar is a free, open-source mobile app from Payatu that is vulnerable on purpose: from insecure storage to RCE and account takeover. Download it and start hunting.
30+
Android Bugs
20+
iOS Bugs
10+
Modules

.png)

Inside the app
See what you’re getting into
Each module is a self-contained target: a short brief, one objective, and a live feature carrying the flaw.

WHAT YOU GET TO BREAK
The vulnerability catalog
50+ modules span every major mobile vulnerability class, beginner to advanced. Here are three the full set ships in the app.
Insecure Data Storage
Storage
Android
iOS
Find what the app leaves lying around in local storage, then read it the way anyone holding the device could.
BEGINNER
One-Click Account Takeover
Storage
Android
iOS
Turn a weak authentication check into control of someone else's account, and see exactly why one tap was enough.
Advanced
Remote Code Execution
RCE
Android
Take attacker-controlled input all the way to code running on the device, the class that ends arguments about severity.
Advanced
Setup
Set the target up properly
A deliberately vulnerable app deserves a deliberate setup: contained, proxied, and on hardware you control.
Android
BugBazaar.apk
Grab the APK from the GitHub releases page - no account needed.
Install on a device or emulator. adb install BugBazaar.apk, or drag it into an Android Studio AVD.
Open the module list and pick your first target. Each module has a short brief in-app.
iOS
iBugBazaar.ipa
Grab the IPA from the iBugBazaar releases page.
Sideload it onto a jailbroken device (or a simulator build) using your preferred tool.
Start with an easy module - insecure storage or logging — to confirm your setup works end to end.
BugBazaar is intentionally vulnerable. Install it on a test device or emulator you control - never on a daily-driver phone.
FAQ
Questions Web Application teams ask us.
What is Web Security Testing?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
What vulnerabilities are tested during a Web Security Assessment?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
How is Web Security Testing different from a vulnerability scan?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
When should we perform Web Security Testing?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
What do we receive after the Web Security Assessment?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
Can Web Security Testing identify business logic vulnerabilities?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.












