The Apple Music Android application (version 1.2.1 and below), does not validate the SSL certificates it receives when connecting to the mobile application login and payment servers.

http://www.info-sec.ca/advisories/Apple-Music.html