Possible vulnerability. Bypassing both 2FA and device list

Recently someone was able to make a purchase with my Apple account.

I had 2FA active and it was not triggered. Additionally, the rouge device did not show up in my device list and when I contacted support and they showed the purchase was made on an iPhone 8. (I have NEVER owned and iPhone .)


This person somehow bypassed both 2FA AND the device list.

No idea how they did it, but this seems like a serious security breach and should be looked into.

iPad Pro, iPadOS 17

Posted on Apr 1, 2025 2:16 PM

Reply
23 replies
Sort By: 

Apr 2, 2025 9:30 AM in response to Punisher2006

You don’t understand how your PayPal account interacts with your Apple Account. You don’t understand what merchant tokens are. You don’t understand how tokens for your PayPal account work. You don’t understand how you bypassed 2FA when you added your PayPal account to your Apple Account.


On a separate but necessary level of understanding is What Apple Pay is and how it’s not your Apple Account. You don’t understand the difference between the Wallet app and your Apple Account and how they do not connect.


I could go on and on but I don’t see the point. You’re convinced you’re right, despite your lack of understanding about payment systems and security surrounding them.


There is a reason your report is being rejected. It’s all the reasons I stated above and more. Sorry to be blunt.

Reply

Apr 2, 2025 4:05 PM in response to Jeff Donald

Jeff Donald wrote:

You don’t understand how your PayPal account interacts with your Apple Account. You don’t understand what merchant tokens are. You don’t understand how tokens for your PayPal account work. You don’t understand how you bypassed 2FA when you added your PayPal account to your Apple Account.

On a separate but necessary level of understanding is What Apple Pay is and how it’s not your Apple Account. You don’t understand the difference between the Wallet app and your Apple Account and how they do not connect.

I could go on and on but I don’t see the point. You’re convinced you’re right, despite your lack of understanding about payment systems and security surrounding them.

There is a reason your report is being rejected. It’s all the reasons I stated above and more. Sorry to be blunt.

Please explain it like I'm 5. I have some brain damage so that may be preventing me from understanding what your trying to say.

Explain how the items show up on my Apple Account.

I understand that when I added PayPal to my payment methods I had to use 2FA to add them.

I understand that any purchases after that from my Apple Account "byass" the PayPal 2FA where it's not asked for again when purchasing from my Apple Account.

I don't understand what the signifiicant diifference is when I say my Apple Account and Apple Pay or the Wallet. Is it just symantics?They seem to all be connected.

I don't use Apple Pay anywhere unless it's already on my iPad. I have never installed it anywherw else. I'm not even sure it's possible to install it on an Android phone which is what I have.

I don't understand how someone used my Apple ID/Account/whatever you want to call it without activating the 2FA that is setup for my Apple Account. If I gave you my Apple password and you tried to login wouldn't part of the process by that 2FA kicks in BEFORE you could actually access ANYTHING in my account, including my payment methods? If I don't either click allow on my iPad or send you the code I received via text, shouldn't you be unable to login fully?

It is a fact that someone added my Apple account on their own iPhone 8. The rep confirmed it and having the purchased items show up as purchases in my account and on the report an issue site confirms it.


I'm not trying to be argumentative for the record. I'm truly trying to understand hat happened and how.


Reply

Possible vulnerability. Bypassing both 2FA and device list

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.