Researchers Discover Bypass ‘Bug’ In iPhone Apple Pay, Visa

September 30, 2021

On Thursday, U.K. academics uncovered mobile security problems in Visa and Apple’s payment mechanisms that could lead to fraudulent contactless payments.

The attacker could bypass the lock screen of an Apple iPhone to access payment services and make contactless transactions.

While the paper points out that the error occurs when Visa cards are set up in express transit mode in the wallet of an iPhone, researchers explain that the problem only applies to Apple Pay and Visa and is caused by the use of a unique code nicknamed “magic bytes.”

The researchers explained that an attack can be triggered by capturing and transferring “magic bytes,” while at the same time changing a number of other variables as soon as a specific victim is nearby.

The researchers said they reached out to Apple and Visa on the issue, and although both parties acknowledge the error, the issue remains unresolved.

According to Andreea-Ina Radu, one of the authors of the study, “Our work shows a clear example of a feature, meant to incrementally make life easier, backfiring and negatively impacting security, with potentially serious financial consequences for users. Our discussions with Apple and Visa revealed that when two industry parties each have partial blame, neither are willing to accept responsibility and implement a fix, leaving users vulnerable indefinitely.”

For more information, read the original story in ZDNet.

Top Stories

Related Articles

December 30, 2025 A fast-moving cyberattack has compromised more than 59,000 internet-facing Next.js servers in less than two days after more...

December 29, 2025 The U.S. National Institute of Standards and Technology (NIST) has warned that several of its Internet Time more...

December 29, 2025 A critical security flaw has been found in LangChain, one of the most widely used frameworks for more...

December 23, 2025 South Korea will require facial recognition scans to open new mobile phone accounts. The new rule is more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn