www.birmingham.ac.uk iPhone Payment Fraud Risk Due to Apple Pay and Visa Vulnerabilities
Article Content
- •Vulnerabilities in Apple Pay and Visa allow unauthorized payments on iPhones.
- •Attackers can exploit 'Express Transit mode' to bypass lock screen security.
- •Apple and Visa have been aware of this issue since 2021 but have not issued a fix.
Research from the University of Birmingham and University of Surrey has revealed vulnerabilities in Apple Pay and Visa that could allow hackers to bypass the iPhone's lock screen and execute unauthorized contactless payments. The flaw primarily affects iPhones using Visa cards in 'Express Transit mode', which is designed for quick payments in transit systems. By exploiting a unique code broadcast by transit gates, attackers can trick the iPhone into thinking it is communicating with a transit system, allowing for transactions of any amount without user authorization. This vulnerability has been known since at least 2021, but Apple and Visa have not implemented a fix, leaving users exposed. While Android devices are not susceptible to this specific attack, the issue highlights significant security concerns in mobile payment systems. The researchers emphasize that usability features intended to enhance convenience can inadvertently compromise security. Current discussions with Apple and Visa have not resulted in accountability or a solution for affected users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…