Home Kripto McDonald’s India Delivery System Security Flaws Risked Sensitive Information
Kripto

McDonald’s India Delivery System Security Flaws Risked Sensitive Information

McDonald’s India Delivery System Security Flaws Risked Sensitive Information

TechCrunch has revealed critical security flaws in McDonald’s India (West & South) delivery system that exposed sensitive customer and driver information. Traceable AI security researcher Eaton Zveare identified these vulnerabilities in the APIs of the McDelivery platform, which powers both the app and website for McDonald’s India (West & South), operated by Hardcastle Restaurants.

The security flaws allowed unauthorized access to customer names, email addresses, and phone numbers, as well as vehicle details, profile pictures, and real-time locations of delivery drivers. Zveare also discovered that the bugs enabled anyone to hijack or redirect orders, track them in real-time, and even place legitimate orders for as little as $0.01. The issues stemmed from the API failing to validate user permissions adequately. Additionally, users could access invoices and submit feedback for orders, further demonstrating the extent of the vulnerabilities.

Zveare reported the flaws to McDonald’s India in July, and fixes were implemented by late September. In a blog post detailing the findings, Zveare noted that the delivery system’s APIs for both the mobile app and website were equally affected, leaving the entire platform exposed to potential exploits.

McDonald’s India assured that a “thorough verification of systems and logs” found no evidence of a customer data breach. “We conduct regular audits and assessments to continuously strengthen our security measures, and have all the necessary enhancements implemented, ensuring all our systems are up to date and secure,” said Sulakshna Mukherjee, a spokesperson for McDonald’s India (West & South), in a statement to TechCrunch.

The company did not disclose how many customers were affected, but Zveare estimated that hundreds of millions of orders were potentially exposed. This incident echoes a 2017 data leak when McDonald’s India (West & South) delivery app exposed the personal information of 2.2 million customers.

Related Articles

YouTube TV App to Get a Redesign This Summer
Kripto

YouTube TV App to Get a Redesign This Summer

YouTube TV will be rolling out a new, customizable multiview feed that...

Threads Expands Advertising Reach to Global Advertisers
Kripto

Threads Expands Advertising Reach to Global Advertisers

Meta’s Threads, a burgeoning social media platform, has announced its expansion of...

Tesla Stock Jumps After Trump’s Comments on China Tariffs and Powell, Despite Weak Earnings
Kripto

Tesla Stock Jumps After Trump’s Comments on China Tariffs and Powell, Despite Weak Earnings

Tesla’s stock soared 5.3% after CEO Elon Musk recently told investors he...

YouTube Celebrates 20 Years and Poised to Become the Top Media Company by Revenue
Kripto

YouTube Celebrates 20 Years and Poised to Become the Top Media Company by Revenue

Twenty years ago, Jawed Karim uploaded his simple 19-second video titled “Me...