Can Payment Request API be abused by Cybercriminals?

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Payment Request API coming to Edge in Creators Update
Simplier Web Payments

With the Payment Request API, payment information is provided by the wallet (once the user has granted consent), as opposed to being collected via a checkout form in the website. The browser mediates all the information passed between the wallet and the merchant.​

Details: Simpler web payments: Introducing the Payment Request API - Microsoft Edge Dev Blog

Online shopping gets even easier: Late last year we introduced a preview implementation of the Payment Request API for Microsoft Edge, which will work with Microsoft Wallet on Windows 10 PCs to make online shopping easier than ever.
On participating web sites, users will have the option to checkout quickly using their payment information stored securely in Microsoft Wallet so they don’t have to navigate through traditional checkout flows and repeatedly enter the same payment and shipping address information.
Source: Microsoft Edge helps you organize your web - Windows Experience Blog

It mentions participating websites, but is it possible for this to be abused by Cybercriminals and Ransomware (although Bitcoin is preferred)? And is this API restricted to Edge, or permitted for Store apps and desktop apps as well?
 
  • Like
Reactions: Deleted member 2913

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top