if I’m reading the source I found correctly, that has got nothing to do with Tap and Pay, where a virtual card is stored/emulated on device via the secure element, instead emulating an Contactless reader and relaying a real card pressed up against the device.
If anything, this attack is a benefit of mobile payments, where you need a second device to perform the attack with, and the user to use verify themselves for the payment to go through.
if I’m reading the source I found correctly, that has got nothing to do with Tap and Pay, where a virtual card is stored/emulated on device via the secure element, instead emulating an Contactless reader and relaying a real card pressed up against the device.
If anything, this attack is a benefit of mobile payments, where you need a second device to perform the attack with, and the user to use verify themselves for the payment to go through.