Researchers have urged iPhone users to remove Visa as a transport card via Apple Pay after uncovering a flaw which they say fraudsters could use to bypass security and make unlimited contactless payments. They claim the vulnerability only happens on Apple Pay when a Visa card is set up as an Express Travel Card, also known as Express Transit mode – a feature intended for owners to tap in and out of public transport without needing to unlock their phone. “There is no need for Apple Pay users to be in danger, but until Apple or Visa fix this they are.”Back-end fraud detection checks were also unable to stop any payments going through in tests carried out by the group. “Visa takes all security threats very seriously, and we work tirelessly to strengthen payment security across the ecosystem.”An Apple spokesperson said: “We take any threat to users’ security very seriously. “Apple Pay users should not have to trade-off security for usability, but at the moment some of them do.”
Source: Irish Examiner September 30, 2021 12:00 UTC