HeadlinesBriefing favicon HeadlinesBriefing.com

Apple Pay Visa Loophole: $10K Heist Requires Stolen iPhone

AppleInsider •
×

A highly specific Visa card vulnerability in Apple Pay's Express Transit mode enabled researchers to steal $10,000 from Marques Brownlee's locked iPhone. The hack required physical device access, a Visa card in Express Transit, and specialized hardware to intercept NFC transaction handshakes.

This man-in-the-middle technique exploited flaws in Visa's security protocols, not Apple's systems. The setup demanded perfect conditions: the iPhone needed to be stolen, placed on an NFC reader connected to the attacker's laptop, and paired with a hacked payment terminal.

Security experts emphasize this scenario is extremely unlikely to affect average users. Visa's fraud protections would refund any unauthorized transactions, and the required circumstances—stolen device, specific card type, and coordinated terminal hacking—make this impractical for real-world theft. Users should keep Express Transit enabled for its convenience rather than disabling it over this improbable threat.