Apple pay 'hack found' - OmniCyber Security (2024)

Apple pay 'hack found' - OmniCyber Security (1)

Businesses and individuals live in a world where cyber-attacks, hacks, and identity and payment fraud are a constant threat.

The latest risk is from unauthorised payments that can be made on locked iPhones. Attackers can bypass the iPhone lock screen to initiate a Visa transaction within Apple’s payments feature.

The issue was discovered by interfering with the Apple Pay feature, which was designed to help commuters pay quickly at ticket barriers with Visa.

What does this mean?

Researchers from the University of Birmingham and the University of Surrey discovered the security threat to Apple users. The vulnerability occurs if you add your Visa card to the ‘Express Transit Mode’ in an iPhone Wallet.

Express Transit Mode is designed to facilitate Apple Pay users (usually commuters) who want to make contactless payments without unlocking their phone, such as when they are passing through a railway or underground’s access turnstile.

The research explains that hackers could manipulate this system to perform contactless payments without having to unlock the screen first.

How did the researchers find this out?

The university’s researchers used off-the-shelf radio equipment to capture a unique code broadcast by the transit gates. This code, named by the researchers as ‘magic bytes,’ is what unlocks Apple Pay and authenticates close-proximity payments.

Researchers were able to use this code to fool the iPhone into thinking it was talking to a transit gate. By broadcasting the magic bytes and changing other fields in the protocol, a regular shop’s smart payment reader was tricked into believing that the iPhone had successfully been unlocked by user authorisation. By using this method, payments of any amount are able to be taken without the iPhone user’s knowledge.

Apple and Visa's responses raise concerns

Apple commented that “We take any threat to users’ security very seriously. This is a concern with a Visa system, but Visa does not believe this kind of fraud is likely to take place in the real world given the multiple layers of security in place.”

The researchers spoke extensively with Visa and Apple but felt that neither accepted responsibility for fixing the vulnerability with the two parties partially to blame. With cyber security weaknesses such as these left unfixed, the only way your e-commerce or online payment accepting business can reduce its risks is to have your online cybersecurity independently reviewed, tested, and protected.

If you don’t want to take any chances with your online security, contact us today, and we can get your business protected.

Contact us..

Related Articles

Apple pay 'hack found' - OmniCyber Security (2)

What Is PCI DSS?

JohnSeptember 3, 2024

The Payment Card Industry Data Security Standard (PCI DSS) ensures that all companies accepting, processing, storing, or transmitting credit card information maintain a secure environment.

Find Out More

Apple pay 'hack found' - OmniCyber Security (4)

What is Ethical Hacking?

JohnAugust 12, 2024

Sometimes the best way to defend is to attack. In cyber security, one of the most effective proactive security measures you can take is to

Find Out More

Apple pay 'hack found' - OmniCyber Security (2024)
Top Articles
AirPods Pro (1st generation) with Wireless Charging Case - Technical Specifications - Apple Support
What can Student Loans Be Used for? | MoneyLion
Ghosted Imdb Parents Guide
Big Spring Skip The Games
Truist Park Section 135
Puretalkusa.com/Amac
Think Of As Similar Crossword
Words From Cactusi
GAY (and stinky) DOGS [scat] by Entomb
Xrarse
Slay The Spire Red Mask
Inside California's brutal underground market for puppies: Neglected dogs, deceived owners, big profits
Signs Of a Troubled TIPM
The Binding of Isaac
Wgu Admissions Login
Vermont Craigs List
Blackwolf Run Pro Shop
Navy Female Prt Standards 30 34
Directions To Advance Auto
No Hard Feelings - Stream: Jetzt Film online anschauen
Petco Vet Clinic Appointment
Zack Fairhurst Snapchat
Heart Ring Worth Aj
Evil Dead Rise Showtimes Near Regal Sawgrass & Imax
Reborn Rich Kissasian
How Long After Dayquil Can I Take Benadryl
Dexter Gomovies
Healthy Kaiserpermanente Org Sign On
Craigslist Sf Garage Sales
Primerica Shareholder Account
Publix Coral Way And 147
134 Paige St. Owego Ny
Mbi Auto Discount Code
Truckers Report Forums
AP Microeconomics Score Calculator for 2023
Crystal Mcbooty
Quake Awakening Fragments
Craigslist List Albuquerque: Your Ultimate Guide to Buying, Selling, and Finding Everything - First Republic Craigslist
Bella Thorne Bikini Uncensored
Barber Gym Quantico Hours
manhattan cars & trucks - by owner - craigslist
Swsnj Warehousing Inc
Phmc.myloancare.com
Dineren en overnachten in Boutique Hotel The Church in Arnhem - Priya Loves Food & Travel
Jimmy John's Near Me Open
Craigslist Indpls Free
Craigslist Monterrey Ca
Turning Obsidian into My Perfect Writing App – The Sweet Setup
Phumikhmer 2022
Invitation Quinceanera Espanol
What Responsibilities Are Listed In Duties 2 3 And 4
Honeybee: Classification, Morphology, Types, and Lifecycle
Latest Posts
Article information

Author: Laurine Ryan

Last Updated:

Views: 6552

Rating: 4.7 / 5 (77 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Laurine Ryan

Birthday: 1994-12-23

Address: Suite 751 871 Lissette Throughway, West Kittie, NH 41603

Phone: +2366831109631

Job: Sales Producer

Hobby: Creative writing, Motor sports, Do it yourself, Skateboarding, Coffee roasting, Calligraphy, Stand-up comedy

Introduction: My name is Laurine Ryan, I am a adorable, fair, graceful, spotless, gorgeous, homely, cooperative person who loves writing and wants to share my knowledge and understanding with you.