Apple Pay Users Could Lose £1,000 per Transaction via MITM Attack

Apple Pay Users Could Lose £1,000 per Transaction via MITM Attack

Apple Pay Users Could Lose £1,000 per Transaction via MITM Attack

Mobile wallet security has become increasingly important as contactless payments continue to replace physical cards for millions of consumers worldwide. Features that prioritize speed and convenience, such as transit payment capabilities, have helped drive widespread adoption of digital wallets, but they also create new opportunities for researchers to identify potential vulnerabilities before they can be exploited at scale. As payment ecosystems become more sophisticated, ensuring strong authentication while preserving a seamless customer experience remains a delicate balancing act.

How the Apple Pay Express Transit Vulnerability Works

Recent research highlighting a potential weakness in Apple Pay’s Express Transit mode underscores the importance of continually evaluating mobile wallet security across the payments ecosystem. The demonstrated attack raises broader questions about where responsibility lies when vulnerabilities involve multiple participants—including device manufacturers, payment networks, and EMV specifications. Although there is no evidence that the exploit has been widely used in the real world, the findings reinforce why collaboration among payment stakeholders is essential to maintaining consumer confidence in contactless payments.

The man-in-the-middle attack vulnerability has been demonstrated by Dr Andreea Radu, the lead researcher at the School of Computer Science at the University of Birmingham. The vulnerability requires that the Apple Pay user have express transit mode enabled, a feature that allows the payment to be initiated at a transit terminal without unlocking the phone. Apple deployed this feature in May of 2019.  One noteworthy point: the attack works through most purses and pockets and modifies the transaction so that it appears the user was authenticated using the Apple biometric of PIN.

Who Is Responsible for the Security Flaw?

One important aspect that isn’t clear is who is responsible for this breach in security. The research team indicates that the flaw is specific to a Visa card within Apple Pay and that neither Apple nor Visa are taking action to fix the flaw. It is unclear if the researchers tested other network cards, such as Amex or Mastercard, to determine If this is a problem in the EMV specification itself or just Visa and Apple’s implementation of EMV:

“However, an experiment conducted by the Universities of Birmingham and Surrey found threat actors are able to exploit a flaw to bypass the Apple Pay lock screen and charge the connected card, in some cases up to £1,000 per transaction, without user authorisation. The owner doesn’t have to leave the device unattended or have it stolen – thieves can also exploit the flaw through a bag or coat, thanks to contactless payment technology.

In a demonstration of the exploit, researchers used an iPhone, an NFC-enabled Android phone, a standard EMV reader payment terminal, and a laptop connected to a Proxmark radio-frequency identification (RFID) scanner.

The Android phone is used as a card emulator to communicate with a payment terminal. Meanwhile, the Proxmark device, connected to a laptop, acts as a reader emulator to communicate with the potential victim’s iPhone, which is led to act as if the transaction is happening with a legitimate transport EMV reader.

Researchers first set up a payment for £1,000 on the payment terminal and ran a script on the laptop to alert the Proxmark RFID scanner to receive the transaction, which then passes it to the payment terminal. Meanwhile, the flaw also manipulates the payment terminal to believe that the victim had authorised the transaction by biometric or PIN verification, enabling the transaction to take place.”

Conclusion

The continued growth of contactless payments makes mobile wallet security a shared responsibility among technology providers, payment networks, financial institutions, merchants, and standards organizations. As new payment features are introduced to improve convenience, ongoing security research plays a vital role in identifying weaknesses before they become widespread threats. Independent academic research helps strengthen the overall payments ecosystem by encouraging vendors to evaluate potential risks and improve existing protections.

The Apple Pay Express Transit findings demonstrate that even mature payment technologies require continuous scrutiny. Whether the vulnerability ultimately stems from Apple Pay, Visa’s implementation, or broader EMV specifications, the research highlights the need for coordinated action whenever multiple parties contribute to the payment experience. Preserving consumer trust will depend on addressing vulnerabilities quickly while continuing to balance security, usability, and innovation in digital payments.

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

Exit mobile version