If you have registered for an account on the McDonald's to place your orders online, we inform you that this account can be easily compromised due to a vulnerability that allows the attacker to steal your password.
Specifically, Dutch software engineer Tijme Gommers discovered a security flaw in the McDonald's website that can be exploited by hackers, thus gaining access to your personal data.
The McDonald's website stores user information in cookies every time you log in so that you don't have to repeat the process over and over again. However, those of you who have not pre-selected this option are safe.
The security researcher explains how this vulnerability can expose users and what information is at risk. "Due to the vulnerability, they can steal and decrypt your password, as well as your name, address, and contact information," he says.
The worst part is that McDonald's has been informed about the vulnerability but has completely ignored it since no fix has been released. Since the vulnerability is still on the website, Tijme Gommers decided to reveal it in order to make noise about the company.
The only thing you can do for now is to avoid saving your details on the website and not use the same password on many different services. There is a high chance that hackers will exploit your other accounts with the stolen details.
We hope McDonald's will act immediately to resolve the problem, as otherwise it will certainly negatively affect the opinion of its consumers.
