Researchers have discovered a way to make fraudulent payments using Apple Pay from a locked iPhone via a Visa card in the digital wallet when the Express Transit feature is enabled.

See also: Brazil: Apple fined because the iPhone 13 comes without a charger?
The method works even if the iPhone is in a bag or someone's pocket and there is no transaction limit.
Examining attacks on contactless payments, researchers at the University of Birmingham and at the University of Surrey in the United Kingdom found that iPhone devices confirm transactions under certain conditions.
To complete a payment, iPhone users must authorize it by unlocking the phone using Face ID, Touch ID, or a password.
However, in certain cases such as payment on public transport, unlocking the device makes the payment process difficult for the user, and thus Apple Pay offers Express Transit, a feature that allows a transaction to be completed without unlocking the device.
Express Transit works for specific services, such as ticket gates, with card readers that send a non‑standard byte sequence that bypasses the Apple Pay lock screen.
The researchers were able to simulate a ticket barrier transaction using a Proxmark device that acts as a card reader that communicates with the target iPhone and an Android with an NFC chip that communicated with a payment terminal.
See also: Apple Pay Later: The service that allows app purchases in monthly installments
The method is an active replay and rebroadcast attack at the hub, where the Proxmark repeats the bytes to the iPhone to deceive it and make it believe it is a ticket‑gate transaction, so user authentication for payment approval is not required.

Examining the issue more closely, the researchers discovered that they could modify the card transaction criteria (CTQ) that are responsible for setting contactless transaction limits. This modification is intended to deceive the card reader into thinking that the authentication step on the mobile device has been successfully completed.
The tests were successful only with iPhone and Visa cards. With Mastercard, a check is performed to ensure that a locked iPhone accepts transactions only from card readers with a merchant transit code.
Testing the method with Samsung Pay, researchers found that transactions are always possible with locked Samsung devices. However, the price is always zero and transit providers charge tickets based on the data related to these transactions.
The findings of this research were sent to both Apple and Visa in October 2020 and May 2021 respectively, but the problem still persists.
See also: VISA: Hackers increasingly use web shells to steal credit card details
The two companies blamed each other, so the vulnerability is still present and can be exploited by malicious actors.
Details of the research are available in a paper titled “Practical EMV Relay Protection,” to be presented at the 2022 IEEE Symposium on Security and Privacy.
