By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: An Apple Pay flaw allows you to empty your account, even with a locked iPhone
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > An Apple Pay flaw allows you to empty your account, even with a locked iPhone
Computing

An Apple Pay flaw allows you to empty your account, even with a locked iPhone

News Room
Last updated: 2026/04/16 at 6:43 PM
News Room Published 16 April 2026
Share
An Apple Pay flaw allows you to empty your account, even with a locked iPhone
SHARE

A spectacular demonstration, led by YouTubers Veritasium and Marques Brownlee, brought a particularly worrying vulnerability to the forefront. By exploiting a function ofApple Paythey managed to simulate a theft of $10,000 on a perfectly locked device. This maneuver, although complex to implementexposes a very real risk for a specific category of users who are often unaware of its existence.

How does a simple transportation feature become a gateway?

The problem lies in the mode « Transport Express » of Apple Pay. Designed to simplify the lives of users on public transport, this option makes it possible to validate a transport ticket without having to authenticate via Face ID or a passcode. It is precisely this convenience that is abused by attackers.

Thanks to an interception technique known as “man in the middle”hackers use specialized equipment to make the device believe that it is interacting with a simple transport terminal. The signal is actually diverted, modified on the fly, then sent to a real payment terminal, thus authorizing an unsolicited transaction of a large amount via this impressive security hole.

Why does this vulnerability only affect certain users?

This attack only works under very specific conditions and therefore does not threaten all owners of an Apple smartphone. It exclusively targets users ofiPhone having configured a Visa network bank card in the “Transport” section of their Apple Wallet digital wallet.

Other systems and networks seem better protected facing this scenario. Samsung devices, for example, check the digital value of the transaction even in transport mode and systematically block any amount greater than zero. For their part, the cartes Mastercard incorporate an additional layer of security, asymmetric encryption, which prevents data manipulation and makes the attack ineffective.

Apple Pay

Who is responsible and how can we protect ourselves effectively?

The situation is in a deadlock for almost five yearsdate of the first revelation of the flaw by cybersecurity researchers. Apple believes that the problem comes from Visa’s payment system, while Visa assures for its part that its fraud detection protocols make this type of attack very unlikely in real conditions. The two giants therefore pass the buck, leaving the vulnerability uncorrected.

The payment company reminds that customers are protected by a policy of “zero liability”guaranteeing a refund in the event of proven fraud. However, to avoid stress and long procedures, the simplest solution remains preventative. It is strongly recommended to deactivate “Express Transport” mode in your device settings, or, failing that, not to associate a card with it. Visa.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Ticketmaster and Live Nation found guilty of overcharging Ticketmaster and Live Nation found guilty of overcharging
Next Article Access Denied
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

China will bring together more than 300 humanoid robots in a half marathon. The goal goes beyond running
China will bring together more than 300 humanoid robots in a half marathon. The goal goes beyond running
Gaming
Access Denied
Blog
Ticketmaster and Live Nation found guilty of overcharging
Ticketmaster and Live Nation found guilty of overcharging
Mobile
How Claude Mythos is changing IT security
How Claude Mythos is changing IT security
News

You Might also Like

YouTube also lets you disable the Shorts feed
Computing

YouTube also lets you disable the Shorts feed

2 Min Read
North Korea quietly ramps up atomic production
Computing

North Korea quietly ramps up atomic production

4 Min Read
will the European sky be empty in a month?
Computing

will the European sky be empty in a month?

5 Min Read

Social Media Analytics Tools for Better Marketing Insights |

7 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?