Thursday, May 15, 2025
No Result
View All Result
Shorouk Express
Advertisement
  • Home
  • World
  • Europe
  • Africa
  • Maghrab
  • Policies
  • Companies
  • Economy
  • Security & Defense
  • Sports
  • Technology
  • Culture
  • Home
  • World
  • Europe
  • Africa
  • Maghrab
  • Policies
  • Companies
  • Economy
  • Security & Defense
  • Sports
  • Technology
  • Culture
No Result
View All Result
Shorouk Express
No Result
View All Result
Home Technology

Bugs in a major McDonald’s India delivery system exposed sensitive customer data | TechCrunch

19 December 2024
in Technology
Reading Time: 2 mins read
0 0
A A
0
Bugs in a major McDonald’s India delivery system exposed sensitive customer data | TechCrunch
Share on FacebookShare on Twitter


A serious McDonald’s supply system in India uncovered the non-public info of its prospects and drivers because of a number of easy safety flaws, TechCrunch has completely realized.

The failings, found by safety researcher Eaton Zveare, have been discovered within the APIs of the supply system related to McDonald’s India (West & South), which is owned by Hardcastle Eating places.

Zveare advised TechCrunch that bugs within the firm’s supply system, McDelivery, meant anybody might entry, hijack, redirect, or real-time monitor orders, or make authentic orders for $0.01, by interacting with the corporate’s API, which apps and web sites use for putting orders and monitoring. It is because the API wasn’t correctly checking to ensure the particular person making requests was allowed to make it. The bugs additionally allowed entry to invoices and supplied the flexibility to submit suggestions for buyer orders.

The safety flaws uncovered McDelivery buyer full names, electronic mail addresses, and cellphone numbers of McDonald’s India (West & South) prospects, and uncovered entry to automobile numbers, profile photos, and monitor the real-time location of the restaurant chain’s drivers delivering orders.

Zveare discovered the vulnerabilities and reported them to the restaurant chain in July. They have been fastened in late September, per the researcher.

McDonald’s India advised TechCrunch {that a} “thorough verification of techniques and logs” confirmed the failings didn’t end in a breach of its buyer knowledge.

“We conduct common audits and assessments to constantly strengthen our safety measures, and have all the mandatory enhancements carried out, guaranteeing all our techniques are updated and safe,” Sulakshna Mukherjee, a spokesperson at McDonald’s India (West & South), stated in an announcement emailed to TechCrunch.

McDonald’s India didn’t disclose the variety of prospects whose info might have been uncovered by the bugs. Nonetheless, the researcher advised TechCrunch that the failings uncovered entry to a whole bunch of hundreds of thousands of orders.

“The McDelivery (West & South) cellular app makes use of the identical actual backend APIs as the web site. Because of this, each have been weak to the identical exploits,” the researcher advised TechCrunch.

This isn’t the primary time McDonald’s India has exploited its prospects’ delicate knowledge. In 2017, the supply app of McDonald’s India (West & South) leaked the non-public info of about 2.2 million prospects.



Source link

Tags: BugscustomerdatadeliveryexposedIndiamajorMcDonaldssensitivesystemTechCrunch
Previous Post

Montana Supreme Court Upholds Historic Youth Climate Lawsuit Win | naked capitalism

Next Post

26 BEST Places To Travel In January (2024)

Related Posts

HUAWEI Watch 5 launched with tech that turns a single tap into a full health scan
Technology

HUAWEI Watch 5 launched with tech that turns a single tap into a full health scan

15 May 2025
Leica can now style your iPhone photos to mimic a pro photographer
Technology

Leica can now style your iPhone photos to mimic a pro photographer

15 May 2025
Now’s a good time to check in on your Steam account security
Technology

Now’s a good time to check in on your Steam account security

15 May 2025
Grok is unpromptedly telling X users about South African genocide | TechCrunch
Technology

Grok is unpromptedly telling X users about South African genocide | TechCrunch

14 May 2025
Google is upgrading Android Auto in 5 useful ways – including a big one for voice inputs
Technology

Google is upgrading Android Auto in 5 useful ways – including a big one for voice inputs

14 May 2025
Modders use reverse engineering to bring Mario Party 4 to PC, more GameCube games to follow
Technology

Modders use reverse engineering to bring Mario Party 4 to PC, more GameCube games to follow

14 May 2025
Next Post
26 BEST Places To Travel In January (2024)

26 BEST Places To Travel In January (2024)

Deadspin | Frustrated Bears stumble into rematch with unbowed Lions

Deadspin | Frustrated Bears stumble into rematch with unbowed Lions

  • Trending
  • Comments
  • Latest
EXPLAINED: Inheritance and gift tax in Spain’s 17 regions in 2025

EXPLAINED: Inheritance and gift tax in Spain’s 17 regions in 2025

4 March 2025
The Global Impact of Middle Eastern Oil – A Story of Power and Politics

The Global Impact of Middle Eastern Oil – A Story of Power and Politics

14 February 2025
How Trade Routes Have Shaped Middle Eastern Economies for Centuries

How Trade Routes Have Shaped Middle Eastern Economies for Centuries

14 February 2025
The Role of Storytelling in Arabic Literature – From Folktales to Modern Novels

The Role of Storytelling in Arabic Literature – From Folktales to Modern Novels

14 February 2025
What happens if I have Spain’s digital nomad visa and I lose my job?

What happens if I have Spain’s digital nomad visa and I lose my job?

18 February 2025
The EU Commission says it banned officials from meeting with lobbyists acting on Huawei's behalf, after the EU Parliament banned Huawei staff from its premises (Edith Hancock/Wall Street Journal)

The EU Commission says it banned officials from meeting with lobbyists acting on Huawei's behalf, after the EU Parliament banned Huawei staff from its premises (Edith Hancock/Wall Street Journal)

24 April 2025
HUAWEI Watch 5 launched with tech that turns a single tap into a full health scan

HUAWEI Watch 5 launched with tech that turns a single tap into a full health scan

15 May 2025
Overdose deaths fell by 30,000 last year — declining in every state except two

Overdose deaths fell by 30,000 last year — declining in every state except two

15 May 2025
Uzbekistan reaching new heights in energy transformation

Uzbekistan reaching new heights in energy transformation

15 May 2025
UK economy grew 0.7 in Q1, but will slow again as trade war bites

UK economy grew 0.7 in Q1, but will slow again as trade war bites

15 May 2025
Leica can now style your iPhone photos to mimic a pro photographer

Leica can now style your iPhone photos to mimic a pro photographer

15 May 2025
London St Pancras power fault hits Eurostar sparking travel chaos

London St Pancras power fault hits Eurostar sparking travel chaos

15 May 2025
Shorouk Express

Stay informed with Shorouk Express - your premier destination for global news, in-depth analysis, and updates on current events. Get the latest news from around the world delivered straight to you.

Categories

  • Africa
  • Companies
  • Culture
  • Economy
  • Europe
  • Health
  • Maghrab
  • Policies
  • Security & Defense
  • society
  • Sports
  • Technology
  • Uncategorised
  • Uncategorized
  • World

Latest Updates

  • HUAWEI Watch 5 launched with tech that turns a single tap into a full health scan
  • Overdose deaths fell by 30,000 last year — declining in every state except two
  • Uzbekistan reaching new heights in energy transformation
  • About Us
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Shorouk Express.
Shorouk Express is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • World
  • Europe
  • Africa
  • Maghrab
  • Policies
  • Companies
  • Economy
  • Security & Defense
  • Sports
  • Technology
  • Culture

Copyright © 2024 Shorouk Express.
Shorouk Express is not responsible for the content of external sites.