A frightening Apple Pay flaw could allow hackers to steal money from your iPhone even when it's locked by exploiting the vulnerability.
, you don’t have to validate with Face ID, Touch ID, or a passcode. Express Transit is meant to be convenient, but it’s also key to this exploit.
As the researchers explain, ticket readers transmit a non-standard sequence of bytes that are capable of bypassing the iPhone lock screen. They refer to these as “magic bytes” in their research paper. This allows Express Transit to function. Apple Pay checks to see if all the requirements are met, and if they are, it processes the payment.
By mimicking a ticket reader, the researchers were able to trick Apple Pay into processing contactless payments. This was only possible with Visa cards, but it was incredibly effective. The researchers say they were able to use an EMV shop reader to make fraudulent payments of any amount from a locked iPhone. They tested up to £1000, but there might not be a limit.Unfortunately, neither Apple nor Visa are doing anything to patch this frightening vulnerability.
We disclosed this attack to both Apple and Visa, and discussed it with their security teams. Apple suggested that the best solution was for Visa to implement additional fraud detection checks, explicitly checking Issuer Application Data and the Merchant Category Code . Meanwhile, Visa observed that the issue only applied to Apple , so suggested that a fix should be made to Apple Pay.
South Africa Latest News, South Africa Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
The big banks that brought you Zelle are building a new digital walletWhat they want you to use instead of Apple Pay or PayPal.
Read more »
America's biggest banks are taking on Apple Pay and PayPal | CNN BusinessAmerica's largest banks announced plans Tuesday for an electronic wallet that will take aim at Apple Pay and PayPal.
Read more »
Apple Pay and PayPal are under the crosshair of major banksSeven banks are uniting their efforts to create a digital wallet competitor to some of the giants in the industry.
Read more »
Eli Apple Says Josh Allen, Stefon Diggs Need Couples Therapy, Offers to PayBengals cornerback Eli Apple didn't hold back on Buffalo Bills duo Josh Allen and Stefon Diggs, offering to pay for them to go to couples therapy after a video of their verbal exchange made waves
Read more »
If you want to use a security key with your Apple account, you’ll need two keysApple just rolled out security key support for Apple IDs.
Read more »
How to find anything on an Apple iPhone, iPad and MacHave a lot of content on your iPhone? Searching can be a hassle, but Kurt 'CyberGuy' Knutsson shows you an easier way to find anything on your Apple device.
Read more »