Researchers find flaw in Apple Pay that lets attackers make a Visa payment with a locked iPhone.
In a video, researchers showed how they make a contactless Visa payment from a locked iPhone by exploiting an Apple Pay feature called "Express Transit", which is designed to help commuters quickly pay for tickets without unlocking their phones. Apple said the matter was "a concern with a Visa system". In order to exploit the flaw the attacker needs to get close to the victim's phone so the attack might be easiest to deploy against a stolen iPhone. Link
Photo credit: Apple