PT-2021-03: Apple Pay authentication and fields validation issues

iOS/iPhone

Severity:

Severity level: Medium
Apple Pay authentication and fields validation issues
Access Vector: Local

CVSS v3.0
Base Score: 5.3
Vector: (AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)

Vulnerability description:

Apple allows payments using Transport Card for amount>0.00, without implementing proper authentication to ensure that only dedicated transport terminals were used for paying on locked or uncharged iPhones.

Advisory status:

October, 2021 - Vendor notification date

Credits:

Timur Yunusov

Threatscape