> Think about it more from the perspective of a jailbroken device being used as a wallet for "cloned" virtual credit cards, transit cards etc. and then using those on NFC readers.
Any reasonable system (i.e. one using public key cryptography) does not allow the attacker to "clone" your virtual cards at all, because they don't have your private key, which never leaves your device. And if they've compromised your device (not their own) sufficiently to extract your private key then the game is over and you've already lost.
Once they have the private key they don't need a jailbroken phone running the official app, they can just speak the NFC protocol directly to the reader and sign with the victim's private key.
> The main point I'm trying to make though is that mobile devices support NFC payments with virtual cards in wallets that are protected by Apple/Google. That's not a use case that is supported on regular PCs, so it's not unreasonable that the security requirements are different.
The difference is that the security requirements should be lower, since it's only used for in-person purchases. Even if the attacker somehow has your private key, to use NFC they would have to show up in person, smile for all the surveillance cameras and risk getting arrested on the spot if the card has already been reported stolen.