McDonald’s App Bug = Unlimited Free Food

Quick Overview

A security researcher named Bob the Hacker discovered multiple critical vulnerabilities in McDonald's systems, including an unlimited points bug for free food, client-side password protection bypass for the Feelgood Design Hub, exposed API keys, insecure executive-level portal access, and coupon reuse bugs in the Cosmic spin-off, with McDonald's slow to respond to most issues.

Key Points: Bob the Hacker discovered an unlimited points bug in the McDonald's app, allowing users to spoof their points balance for free food, as the "server does not verify your points balance at all." The McDonald's Feelgood Design Hub, a confidential marketing platform, was initially protected only by client-side passwords, leading to easy unauthorized access. After a patch, a new vulnerability allowed creating accounts to access hidden functionality and retrieve an admin password "in plain text," revealing McDonald's "magic bell" API key. Bob gained access to corporate executive-level portals using "credentials of a mere crew member," enabling him to "search for any McDonald's employee globally, even up to the level of CEO, and hamburgle their personal details." McDonald's spin-off restaurant, Cosmic, had a bug that allowed reusing a "coupon only meant for new customers as many times as you want, giving you an unlimited number of free drinks." McDonald's removed its security.txt file, making it difficult for researchers to report vulnerabilities, though Bob eventually contacted the company and most issues were fixed.

Context: This analysis focuses on security vulnerabilities discovered within McDonald's digital systems by a researcher known as "Bob the Hacker." The transcript details a series of critical flaws that allowed for unauthorized access to sensitive platforms, manipulation of loyalty points for free food, and exposure of internal data, highlighting significant security oversights by the fast-food giant. Additionally, it briefly touches upon a separate cyber incident involving the compromise of a North Korean hacker's computer.

Raw markdown version of this recap