Visa Cards on Locked iPhones Vulnerable to $10,000 Security Flaw
A recent study by researchers at the University of Birmingham and the University of Surrey has uncovered a security flaw in Apple's Express Transit feature, which allows users to make contactless payments without unlocking their iPhone. The vulnerability, which was first publicly documented in September 2021, can be exploited using NFC relay hardware and a custom Python script to silently charge a Visa card configured as an Express Transit card inside Apple Wallet.
The researchers demonstrated the attack by spoofing a transit gate signal near a locked iPhone, convincing it that it was paying a subway fare. The relay then modified the transaction amount and forwarded it to a real point-of-sale terminal nearby, resulting in unauthorized contactless payments being made on the locked device.
The study found that no authentication of any kind was required for these transactions, which can reach up to $10,000. Apple has argued that the problem lies in Visa's EMV contactless protocol implementation, not in Apple Pay's core design. Visa points to its zero-liability policy, which means unauthorized charges should be reimbursed if reported promptly.
The fix for this vulnerability is available in Settings and takes less than a minute to apply: set Express Transit Card to None or assign a non-Visa card to that slot. Users are also advised to review their Visa card statements for unfamiliar high-value contactless charges and dispute them under Visa's zero-liability protection.