What justizin said. Also, let's say that I am able to MitM your connection to apple.com. You are a brand new customer, credit card in hand, ready to buy yourself a brand new $5,000 Mac Pro, and a couple of Cinema displays. You open up Chrome, go to apple.com, but instead of getting the real deal, you get my slightly modified version. The change? I run a regex on all the HTML served (that's right, I'm a real h@x0r, and regex my HTML like a boss) that does s/store\.apple\.com/apple-store.com/g. Now, apple-store.com has its own valid SSL cert, so you get the nice green bar when you get to
https://apple-store.com. This site is mine, and all it does is serve the content from the legitimate store.apple.com, except it also injects a small script into the payment form. As soon as you type in your credit card info, it is mine. Moreover, I know exactly how much you spent, and maybe I even allow you to place the order, get all the confirmations, etc. You won't know that something went wrong until I sell your CC number on the black market and some guy in Uzbekistan buys himself an iPhone 6 Plus with your money.
Edit: apple-store.com is obviously a real site, so let's say I find something just as legitimately looking as that.