Ethical Hacking News
Researchers at the University of Massachusetts Amherst have discovered a vulnerability in Visa's EMV kernel that allows attackers to revive expired contactless credit cards by exploiting an unsigned expiry field. The attack has significant implications for the security of contactless payment systems, and several countermeasures are proposed to prevent it in the future.
Researchers at the University of Massachusetts Amherst discovered a vulnerability in Visa's EMV kernel. The vulnerability allows attackers to exploit an unsigned expiry field, effectively reviving expired contactless credit cards. The attack was demonstrated at USENIX Security 2026 and has significant implications for the security of contactless payment systems. The attack can be carried out by exploiting a specific design decision in Visa's Kernel 3. Countermeasures proposed include binding the expiry date cryptographically and requiring terminals to compare both expiry representations. The discovery highlights the importance of ongoing research and testing in contactless payments.
A recent discovery by researchers at the University of Massachusetts Amherst has shed light on a previously unknown vulnerability in Visa's EMV (Europay, Mastercard, and Visa) kernel, which is used by contactless payment protocols. The vulnerability, which was discovered by Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza, allows attackers to exploit an unsigned expiry field in Visa's EMV kernel, effectively reviving expired contactless credit cards.
The researchers demonstrated the attack at USENIX Security 2026 in Baltimore, and their findings have significant implications for the security of contactless payment systems. The attack works by exploiting a specific design decision in Visa's Kernel 3, which sends the issuer a Terminal Verification Results value filled with zeros. This means that the bank cannot tell whether the terminal checked the card's expiry date or whether that check failed, allowing the attacker to approve the transaction without seeing what the terminal actually detected.
The researchers tested their attack on three banks with expired and replaced physical Visa cards and found that two of the banks accepted the modified transactions at various amounts, while the third bank detected the modification and declined the transaction. They also found that attackers could change the Consumer Device Cardholder Verification Method flag at five US banks, allowing them to modify the payment data without being detected.
The researchers propose several countermeasures to prevent this type of attack in the future, including binding the expiry date cryptographically to an issuer-verifiable signature, requiring terminals to compare both expiry representations and making mismatches visible to the issuer, and having issuers authorize against the PAN-and-expiry combination rather than the PAN alone.
The discovery of this vulnerability highlights the importance of ongoing research and testing in the field of contactless payments. It also serves as a reminder that even seemingly secure payment systems can have vulnerabilities that can be exploited by attackers.
Related Information:
https://www.ethicalhackingnews.com/articles/Exploiting-the-Vulnerabilities-of-Contactless-Payments-A-New-Attack-on-Visas-EMV-Kernel-ehn.shtml
https://securityaffairs.com/197663/hacking/your-shredded-visa-card-may-still-work-at-the-checkout.html
Published: Fri Aug 21 13:59:24 2026 by llama3.2 3B Q4_K_M