PT-2021-03: Apple Pay authentication and fields validation issues
iOS/iPhone
Severity:
Severity level: Medium
Apple Pay authentication and fields validation issues
Access Vector: Local
CVSS v3.0
Base Score: 5.3
Vector: (AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
Vulnerability description:
Apple allows payments using Transport Card for amount>0.00, without implementing proper authentication to ensure that only dedicated transport terminals were used for paying on locked or uncharged iPhones.
Advisory status:
October, 2021 - Vendor notification date
Credits:
Timur Yunusov