Researchers Discover Bypass ‘Bug’ In iPhone Apple Pay, Visa

Share post:

On Thursday, U.K. academics uncovered mobile security problems in Visa and Apple’s payment mechanisms that could lead to fraudulent contactless payments.

The attacker could bypass the lock screen of an Apple iPhone to access payment services and make contactless transactions.

While the paper points out that the error occurs when Visa cards are set up in express transit mode in the wallet of an iPhone, researchers explain that the problem only applies to Apple Pay and Visa and is caused by the use of a unique code nicknamed “magic bytes.”

The researchers explained that an attack can be triggered by capturing and transferring “magic bytes,” while at the same time changing a number of other variables as soon as a specific victim is nearby.

The researchers said they reached out to Apple and Visa on the issue, and although both parties acknowledge the error, the issue remains unresolved.

According to Andreea-Ina Radu, one of the authors of the study, “Our work shows a clear example of a feature, meant to incrementally make life easier, backfiring and negatively impacting security, with potentially serious financial consequences for users. Our discussions with Apple and Visa revealed that when two industry parties each have partial blame, neither are willing to accept responsibility and implement a fix, leaving users vulnerable indefinitely.”

For more information, read the original story in ZDNet.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Cisco Duo’s Multifactor Authentication service compromised by social engineering attack

Cisco Duo, a prominent provider of multifactor authentication (MFA) services, has fallen victim to a cyberattack targeting one...

Cyber Security Today, April 17, 2024 – More suspicious attempts to take over open source projects, a data theft at a Cisco Duo partner,...

This episode reports on security updates from Delinea and PuTTY, and reports on bad bots and threat actors going after Zoo

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways