Researchers in the UK have found a bug in Apple Pay that allows hackers to make contactless payments from your iPhone . Group members from the University of Birmingham and the University of Surrey published an article on Thursday (30) describing the method by which this flaw can be exploited. Hackers can even bypass an iPhone’s lock screen.
The r Express Transit feature that Apple first introduced in iOS 12.3 seems to be the culprit. With it, users can quickly pay for trips on public transport with a card in the Wallet application. But I don’t need to validate with Face ID, Touch ID or a password. With convenience came the breach in security. How do they explain the researchers, ticket readers transmit a non-standard sequence of bytes that are able to bypass the iPhone’s lock screen. By imitating a ticket reader, the researchers managed to trick Apple Pay into processing contactless payments — although they have only been able to do this with Visa cards. The researchers were able to use a reader to do this fraudulent payments of any amount from a locked iPhone. They have tested up to £1000 (about R$7,200), but there may not be a limit.
Apple 01 Oct Apple 01 Oct
For now, neither Apple nor Visa have officially commented on the situation, nor do they seem to be leading a solution to the flaw.
Have you ever had security issues with payment apps? Leave your comment!
Note: This article has been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at the original source Click Here