Researchers Discover Bypass ‘Bug’ In iPhone Apple Pay, Visa

Share post:

On Thursday, U.K. academics uncovered mobile security problems in Visa and Apple’s payment mechanisms that could lead to fraudulent contactless payments.

The attacker could bypass the lock screen of an Apple iPhone to access payment services and make contactless transactions.

While the paper points out that the error occurs when Visa cards are set up in express transit mode in the wallet of an iPhone, researchers explain that the problem only applies to Apple Pay and Visa and is caused by the use of a unique code nicknamed “magic bytes.”

The researchers explained that an attack can be triggered by capturing and transferring “magic bytes,” while at the same time changing a number of other variables as soon as a specific victim is nearby.

The researchers said they reached out to Apple and Visa on the issue, and although both parties acknowledge the error, the issue remains unresolved.

According to Andreea-Ina Radu, one of the authors of the study, “Our work shows a clear example of a feature, meant to incrementally make life easier, backfiring and negatively impacting security, with potentially serious financial consequences for users. Our discussions with Apple and Visa revealed that when two industry parties each have partial blame, neither are willing to accept responsibility and implement a fix, leaving users vulnerable indefinitely.”

For more information, read the original story in ZDNet.

SUBSCRIBE NOW

Related articles

MIT students exploit blockchain vulnerability to steal 25 million dollars

Two MIT students have been implicated in a highly sophisticated cryptocurrency heist, where they reportedly exploited a vulnerability...

Cyber Security Today, May 15, 2024 – Ebury botnet still exploits Linux servers, Microsoft, SAP and Apple issue security updates

The Ebury botnet continues to exploit Linux servers, Microsoft, SAP and Apple issue security updates, and more. Welcome to...

Employee errors still predominant cause of data breaches: Verizon Report

In the latest 2024 Verizon Data Breach Report (DBIR), it has been revealed that employee errors remain the...

Black Basta has compromised over 500 organizations globally:CISA

The Cybersecurity and Infrastructure Security Agency (CISA) along with the FBI reported that the Black Basta ransomware group...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways