The researchers from the University of Birmingham and the University of Surrey discovered the fact that iphone devices are able to confirm transactions under certain conditions.
Unfortunately, it can be considered that this method is similar to a digital version of pickpocketing, as it is able to function over the air even if the iPhone is in a bag or in someone’s pocket and there is no transaction limit.
How Does It Work?
Usually, in order for a payment to go through, an iPhone user needs to authorize it by unlocking the phone using the Face ID, Touch ID, or a passcode.
Express Transit uses card readers that send a non-standard sequence of bytes to circumvent the Apple Pay lock screen for specialized services like ticket gates.
This feature can be leveraged to bypass the Apple Pay lock screen, and illicitly pay from a locked iPhone, using a visa card, to any EMV reader,