Apple Pay disabled due to security modifications

I am unable to add a credit card on my 2021 M1 iMac. In System Settings → Wallet & Apple Pay I see "Apple Pay has been disabled because the security settings of this Mac were modified." I can pay with Apple Pay if I authenticate with my watch, but not with touchid.


I ran through Apple's suggested solutions to no avail. After a lot of further debugging and log analysis I found the blockage. It thinks another user is controlling my PassKit. I am the only user. My MacBook does not have this problem.


macOS 27.0.1 (26A434)


LocalAuthentication:

"KEXT check failed"

Subcode=17


PassKit:

PKSecureElementOwnershipStateOwnedByOtherUser


Payment capability:

canMakeLocalPayments: 0

canMakeRemotePayments: 1


Boot policy:

Full Security

3rd Party Kexts Disabled

SIP Enabled

Signed System Volume Enabled

auxp/auxi/auxr absent


Safe Mode:

Same failure


Has anyone else encountered this failure? How did you resolve it?

iMac (M1, 2021)

Posted on Sep 29, 2026 11:21 PM

Reply
Question marked as Top-ranking reply

Posted on Sep 30, 2026 3:16 AM

I’ve seen this reported a few times over the years. The provisioning is generally resolved by creating a new test user (can be deleted later), start adding a card, but don’t finish the process. Then switch user and attempt to provision a card. A warning pops up about another user and do you want to disable the other user. Say yes, disable and finish provisioning your cards. Then delete other user account.

5 replies
Question marked as Top-ranking reply

Sep 30, 2026 3:16 AM in response to MontyWilliams

I’ve seen this reported a few times over the years. The provisioning is generally resolved by creating a new test user (can be deleted later), start adding a card, but don’t finish the process. Then switch user and attempt to provision a card. A warning pops up about another user and do you want to disable the other user. Say yes, disable and finish provisioning your cards. Then delete other user account.

Sep 30, 2026 4:34 PM in response to Jeff Donald

While that suggestion worked fine:


Secure Element: OwnedByUser

CoreKDL/LA: succeeds

Apple Pay: works

3 cards added


The problem came back after a reboot:

Secure Element: OwnedByUser <-- repair persisted

CoreKDL/LA: KEXT check failed <-- failure returned

Apple Pay: disabled


Since I was able to successfully add the cards before I rebooted, I can live with adding new cards being disabled after I rebooted. The three cards work for payment and I can repeat the hack if I need to update my saved cards. I primarily use my MacBook which doesn't have this issue.


It appears Apple Pay authentication policy could not successfully complete its CoreKDL/SEP Kext Deny List check.


coreauthd

-> CoreKDL updateKDLToLatestVersionWithError:

-> finds installed KextDenyList version 31

-> obtains AppleKextDenyList.der

-> KDLIOKitClient updateKDLFromPath:

-> KDLIOKitClient performCommand:

-> kernel/SEP returns 0x4b444c09


Apple Pay disabled due to security modifications

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.