50+ planted vulnerabilities. Your job: find them.

BugBazaar is a free, open-source mobile app from Payatu that is vulnerable on purpose: from insecure storage to RCE and account takeover. Download it and start hunting.
30+
Android Bugs
20+
iOS Bugs
10+
Modules
Person holding a smartphone displaying the BugBazaar app menu, seated at a desk with an open laptop showing a Payatu security findings dashboard, an open notebook with a pen, a desk calendar showing June 2004, and a desk lamp.Person holding a smartphone displaying BugBazaar app interface, sitting at a desk with an open laptop showing Payatu vulnerability findings dashboard, a notebook with a pen, and a desk calendar in the background.Person holding a smartphone displaying the BugBazaar app interface with menu options, sitting at a desk with an open notebook and pen. On the desk is a laptop showing the PAYATU findings dashboard with security scan results, vulnerability statuses, and a calendar showing June 6, 2024, in the background.
Inside the app

See what you’re getting into

Each module is a self-contained target: a short brief, one objective, and a live feature carrying the flaw.
Split screen showing two windows: left is a mobile app named BugBazaar displaying products like Old Town Camera, Dumb Watch, Skate-Board, A Lazy Bicycle, PineApple iPhone, and Z Box Gaming Controller with prices; right is a command prompt window running adb backup commands and showing output of file listings and backup progress.
WHAT YOU GET TO BREAK

The vulnerability catalog

50+ modules span every major mobile vulnerability class, beginner to advanced. Here are three the full set ships in the app.
Icon of a database represented by three stacked cylinders with a red dot on the second cylinder and a black X symbol near the bottom right indicating a database error or failure.

Insecure Data Storage

Storage
Android
iOS
Find what the app leaves lying around in local storage, then read it the way anyone holding the device could.
BEGINNER
A stylized black clock with a red dot near the center and simple black tick marks around the face on a light pink background.

One-Click Account Takeover

Storage
Android
iOS
Turn a weak authentication check into control of someone else's account, and see exactly why one tap was enough.
Advanced
Icon with a red dot at the center connected by black lines to two black dots below, and two black curved lines arcs above the red dot resembling a wireless signal.

Remote Code Execution

RCE
Android
Take attacker-controlled input all the way to code running on the device, the class that ends arguments about severity.
Advanced
Setup

Set the target up properly

A deliberately vulnerable app deserves a deliberate setup: contained, proxied, and on hardware you control.

Android

BugBazaar.apk
01
Grab the APK from the GitHub releases page - no account needed.
02
Install on a device or emulator. adb install BugBazaar.apk, or drag it into an Android Studio AVD.
03
Open the module list and pick your first target. Each module has a short brief in-app.

iOS

iBugBazaar.ipa
01
Grab the IPA from the iBugBazaar releases page.
02
Sideload it onto a jailbroken device (or a simulator build) using your preferred tool.
03
Start with an easy module - insecure storage or logging — to confirm your setup works end to end.
Lowercase letter i in red circle, symbol for information.
BugBazaar is intentionally vulnerable. Install it on a test device or emulator you control - never on a daily-driver phone.
FAQ

Questions Web Application teams ask us.

What is Web Security Testing?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
What vulnerabilities are tested during a Web Security Assessment?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
How is Web Security Testing different from a vulnerability scan?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
When should we perform Web Security Testing?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
What do we receive after the Web Security Assessment?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
Can Web Security Testing identify business logic vulnerabilities?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.