Researchers: a flaw in Apple Pay lets attackers make a Visa payment with a locked iPhone in Express Transit mode; Apple calls it “a concern with a Visa system”
Large unauthorised contactless payments can be made on locked iPhones by exploiting how an Apple Pay feature designed … Source: TimeTrust .
Context & Ripple Effects
Apple Pay’s earlier fraud episodes were tied to banks’ card-verification procedures rather than a failure of Apple’s encryption, while another report showed that adding stolen card details to a wallet could make online fraud usable at physical checkouts. The new research similarly places the weak point at the boundary between the wallet, card network and contactless-payment rules.
Visa’s contactless technology was part of the infrastructure expected to support Apple Pay’s European rollout. Apple’s attribution of the locked-phone payment flaw to Visa therefore makes the incident a test of how payment-network controls behave when a wallet feature is designed to work without unlocking the device.
First-order effects
- Visa faces immediate scrutiny over the system behavior identified by researchers, while Apple must address a payment risk affecting iPhone users despite assigning responsibility to Visa.
- iPhone users with Visa cards are exposed to unauthorized contactless-payment attempts through Express Transit under the conditions described by the researchers.
Second-order effects
- Banks and card issuers may reassess verification and fraud controls for wallet-based contactless transactions, echoing the earlier bank-verification loophole associated with Apple Pay fraud.
- Samsung Pay’s earlier reported token-skimming weakness shows that mobile-wallet providers and card networks share a broader incentive to harden the handoffs between payment credentials, devices and transaction authorization.
Third-order effects
- The incident reinforces that mobile-payment security is governed by a stack of wallet software, issuer checks and network rules, making clear accountability harder when one layer’s convenience feature exposes another layer’s control gap.
- If similar disclosures persist, payment networks and wallet operators will face pressure to make locked-device and express-payment authorization rules more tightly coordinated rather than treating fraud prevention as a single party’s responsibility.
The trend: Mobile-wallet adoption is shifting payment-security risk toward the interfaces between device features, card-network rules and issuer verification.