Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»‘123456’ password exposed information for 64 million McDonald’s job applicants
    Security

    ‘123456’ password exposed information for 64 million McDonald’s job applicants

    PineapplesUpdateBy PineapplesUpdateJuly 11, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    ‘123456’ password exposed information for 64 million McDonald’s job applicants
    Share
    Facebook Twitter LinkedIn Pinterest Email

    ‘123456’ password exposed information for 64 million McDonald’s job applicants

    Cyber ​​security researchers discovered a vulnerability in McDonald’s, McDonald’s Chatbott Job Application Platform, highlighting the individual information of more than 64 million job applicants across the United States.

    The defect was discovered by safety researchers Ian Carol and Sam Curry, who found that the administrator panel of the chatbot used a test franchise, which was preserved by a login name “123456” and a password of “123456”.

    Mchire, operated by Paradox.ai and is used by about 90% of the McDonald’s franchise, accepts job applications through a chatbot called Olivia. Applicants can submit names, email addresses, phone numbers, home addresses and availability, and are required to complete a personality test as part of the job application process.

    Once logged in, the researchers submitted a job application to the test franchise to see how the process works.

    During this test, he noticed that the HTTP requests were sent to API & Point/API/Lead/CEM-Xhr, which used a parameter lead_ID, which was 64,185,742 in his case.

    Researchers found that by increasing and decreasing the lead_ID parameters, they were able to highlight the personal data of full chat tape, session tokens and real job applicants who were first applicable to McHere.

    This type of defect is called an IDOR (unprotected direct object reference) vulnerability, when an application exposes internal object identifiers, such as a record number, without verifying whether the user is really authorized to reach data.

    “During a cursory security review of a few hours, we identified two serious issues: McHeire Administration Interface for the owners of the restaurant accepted the default credentials 123456: 123456, and an unsafe direct object reference (IDOR) on an internal API allowed us to use any contact and chat,” Carol. Explained in a rightup About the defect.

    “Together they allowed us and someone else with a McHare account and access to any inboxes to regain personal data of more than 64 million applicants.”

    In this case, in a request, the lead_ID number was raised or reduced or sensitive data related to other applicants was returned, as the API failed to check whether the user had access to data.

    Exploitation of Ider bug to see McDonald's job applications
    Exploitation of Ider bug to see McDonald’s job applications

    The issue was reported to Paradox.ai and McDonalds on 30 June.

    McDonald’s accepted the report within an hour, and the default administrator Creedians were soon disabled.

    McDonald’s said, “We are disappointed with this unacceptable vulnerability from a third-party provider, Paradox.ai. As soon as we learned about the issue, we made Paradox.ai mandatory to immediately remove the issue, and it was resolved on the same day that we were told,” McDonldes told. Wire In a statement about research.

    Paradox deployed a fix to address the Ider Flaw and confirmed that vulnerability was reduced. Paradox.ai has since said that it is reviewing its system to prevent similar major issues from recurring.


    Tines needle

    While cloud attacks can be more sophisticated, the attackers still succeed with surprisingly simple techniques.

    Drawing by the detection of Vij in thousands of organizations, this report reveals the 8 major techniques used by Claude-Floid danger actors.

    applicants exposed information job McDonalds million password
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBitcoin hits Ath as dozens of treasurer
    Next Article AI Leadership Development Sells Places Practice Labs Torch
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    McDonald’s CEO predicts these 3 big food trends for 2026

    January 15, 2026
    Startups

    Verizon outage affects more than 2 million users: What ‘SOS’ means, refunds, more updates

    January 15, 2026
    Startups

    Former Bolt CEO Maju Kuruvilla’s startup triples in valuation to $100 million

    January 9, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views

    Yes, this was the original voice of the Garat in the trailer for the thief VR

    June 16, 20250 Views

    Best LC10 loadout in call of duty: Warzone

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.