iPhone Payment Fraud Risk Due to Apple Pay and Visa Vulnerabilities

iPhone Payment Fraud Risk Due to Apple Pay and Visa Vulnerabilities

First seen 15 Apr 2026, 23:46 UTC 9To5Googlewww.birmingham.ac.ukDaringfireball 75% similarity 64.5

Article Content

Browse articles
ThreatCluster

Research from the University of Birmingham and University of Surrey has revealed vulnerabilities in Apple Pay and Visa that could allow hackers to bypass the iPhone's lock screen and execute unauthorized contactless payments. The flaw primarily affects iPhones using Visa cards in 'Express Transit mode', which is designed for quick payments in transit systems. By exploiting a unique code broadcast by transit gates, attackers can trick the iPhone into thinking it is communicating with a transit system, allowing for transactions of any amount without user authorization. This vulnerability has been known since at least 2021, but Apple and Visa have not implemented a fix, leaving users exposed. While Android devices are not susceptible to this specific attack, the issue highlights significant security concerns in mobile payment systems. The researchers emphasize that usability features intended to enhance convenience can inadvertently compromise security. Current discussions with Apple and Visa have not resulted in accountability or a solution for affected users.

Key Points: • Vulnerabilities in Apple Pay and Visa allow unauthorized payments on iPhones. • Attackers can exploit 'Express Transit mode' to bypass lock screen security. • Apple and Visa have been aware of this issue since 2021 but have not issued a fix.

ThreatCluster AI How this analysis works

Timeline

2021-01-01
Vulnerability first identified by researchers
2026-04-15
Research findings published by University of Birmingham and University of Surrey
Recent
Discussions with Apple and Visa ongoing without resolution

Community

Browse all →

Tracked Entities in This Story