{"id":394497,"date":"2026-04-16T02:35:10","date_gmt":"2026-04-16T02:35:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/il\/394497\/"},"modified":"2026-04-16T02:35:10","modified_gmt":"2026-04-16T02:35:10","slug":"android-phones-arent-at-risk-of-iphone-tap-to-pay-transit-attack","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/il\/394497\/","title":{"rendered":"Android phones aren&#8217;t at risk of iPhone tap-to-pay transit attack"},"content":{"rendered":"<p>\t<img width=\"1600\" height=\"800\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/04\/iphone-tap-to-pay-vulnerability-veritasium.webp.png\" class=\"skip-lazy wp-post-image\" alt=\"\"  decoding=\"async\" fetchpriority=\"high\"\/><\/p>\n<p>For the past five years, a tap-to-pay vulnerability on iPhone has been known and has now been highlighted in an in-depth video, but your Android phone is not at risk for this.<\/p>\n<p>Tap-to-pay is basically everywhere now and, generally, is considered quite secure. In <a href=\"https:\/\/www.youtube.com\/watch?v=PPJ6NJkmDAo\" rel=\"nofollow noopener\" target=\"_blank\">a new Veritasium video<\/a>, a long-standing vulnerability that allows very large purchases without even unlocking the phone is detailed. <\/p>\n<p>The sophisticated \u201chack\u201d works by tricking the phone into thinking it is talking to a transit system, as special modes on both Android phones and iPhones will bypass the usual requirement for unlocking your device in this particular instance, while also working offline for the sake of underground transit systems where network connections may be spotty. <\/p>\n<p>But iPhones are the only ones vulnerable here. <\/p>\n<p>\tAdvertisement &#8211; scroll for more content<\/p>\n<p>\u201cExpress mode,\u201d as it is called on iPhone, allows transit systems to bypass the lockscreen, while a flaw in how Visa handles big purchases will allow for those larger purchases not to be flagged when used in a transit setting like this \u2013 it doesn\u2019t happen with other processors. The process involves some special hardware (pictured above, as seen in <a href=\"https:\/\/www.youtube.com\/watch?v=PPJ6NJkmDAo\" rel=\"nofollow noopener\" target=\"_blank\">the video<\/a>), as well as a rooted Android phone to act as a card emulator. Apple pointed to Visa as the root of the problem, where the payment processor believes this is unlikely to happen in a real-world setting, and says such an attack would be covered under the <a href=\"https:\/\/www.visa.com\/en-us\/personal\/security\/zero-liability-policy\" rel=\"nofollow noopener\" target=\"_blank\">Visa Zero Liability Policy<\/a>. Apple and Visa have both been aware of this vulnerability <a href=\"https:\/\/www.birmingham.ac.uk\/news-archive\/2021\/visa-and-apple-pay-vulnerabilities-leaves-iphone-users-open-to-payment-fraud\" rel=\"nofollow noopener\" target=\"_blank\">since 2021<\/a>. Visa, at one point, called rooting an Android phone a \u201cdifficult\u201d process as one reason this is unlikely to happen \u2013 take that as you will.<\/p>\n<p>The entire video is well worth a watch, but what we wanted to highlight here is that, as it stands today, Android phones are not vulnerable to this specific attack.<\/p>\n<p>As the video <a href=\"https:\/\/youtu.be\/PPJ6NJkmDAo?t=904\" rel=\"nofollow noopener\" target=\"_blank\">points out<\/a>, Samsung will flag large purchases made through transit modes. Google meanwhile, has an additional layer of security. Google Wallet <a href=\"https:\/\/support.google.com\/wallet\/answer\/12059519\" rel=\"nofollow noopener\" target=\"_blank\">will allow<\/a> for payments with a locked device, but <a href=\"https:\/\/developers.google.com\/wallet\/tickets\/open-loop\/mobile-features\/skip-device-unlock\" rel=\"nofollow noopener\" target=\"_blank\">does require<\/a> the screen to be turned on. Google <a href=\"https:\/\/9to5google.com\/2025\/05\/18\/google-wallet-app-verify\/\" rel=\"nofollow noopener\" target=\"_blank\">has been further<\/a> locking down the Wallet app with biometrics, even outside of payments.<\/p>\n<p>More on Google Wallet:<\/p>\n<p>Follow Ben:\u00a0<a href=\"https:\/\/twitter.com\/NexusBen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Twitter\/X<\/a>,\u00a0<a href=\"https:\/\/www.threads.net\/@nexusben\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Threads<\/a>, <a href=\"https:\/\/bsky.app\/profile\/nexusben.com\" rel=\"nofollow noopener\" target=\"_blank\">Bluesky<\/a>, and\u00a0<a href=\"https:\/\/www.instagram.com\/nexusben\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Instagram<\/a><\/p>\n<p>\t\t<a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/google.com\/preferences\/source?q=https:\/\/9to5google.com\" aria-label=\"Add 9to5Google as a preferred source on Google\"><br \/>\n\t\t\t<img decoding=\"async\" class=\"google-preferred-source-badge-dark\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2025\/09\/google-preferred-source-badge-dark.png\" alt=\"Add 9to5Google as a preferred source on Google\"\/><br \/>\n\t\t\t<img decoding=\"async\" class=\"google-preferred-source-badge-light\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2025\/09\/google-preferred-source-badge-light.png\" alt=\"Add 9to5Google as a preferred source on Google\"\/><br \/>\n\t\t<\/a><\/p>\n<p class=\"disclaimer-affiliate\">FTC: We use income earning auto affiliate links. <a href=\"https:\/\/9to5mac.com\/about\/#affiliate\" rel=\"nofollow noopener\" target=\"_blank\">More.<\/a><\/p>\n<p><a href=\"https:\/\/bit.ly\/4dZciVW\" rel=\"nofollow noopener\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-710515\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/04\/1776306910_491_750x150-1.jpg\" alt=\"\" width=\"700\" height=\"140\"\/><\/a>\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script async src=\"\/\/www.instagram.com\/embed.js\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"For the past five years, a tap-to-pay vulnerability on iPhone has been known and has now been highlighted&hellip;\n","protected":false},"author":2,"featured_media":394498,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[85,46,321,125],"class_list":{"0":"post-394497","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile","8":"tag-il","9":"tag-israel","10":"tag-mobile","11":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/394497","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/comments?post=394497"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/394497\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media\/394498"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media?parent=394497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/categories?post=394497"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/tags?post=394497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}