Last seen July 11, 2025

McHire AI hiring tool default '123456' administrative credentials Vulnerability

A critical security flaw in McDonald's McHire AI hiring tool leveraged default '123456' administrative credentials combined with an Insecure Direct Object Reference (IDOR) vulnerability in an internal API. This exploit allowed researchers to access and potentially expose sensitive Personally Identifiable Information (PII) for millions of job applicants, including chat histories and contact details.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

A critical security flaw in McDonald's McHire AI hiring tool leveraged default '123456' administrative credentials combined with an Insecure Direct Object Reference (IDOR) vulnerability in an internal API. This exploit allowed researchers to access and potentially expose sensitive Personally Identifiable Information (PII) for millions of job applicants, including chat histories and contact details.

Why This Matters

Publisher reporting describes a security event affecting pii. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether pii is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Jul 11, 2025 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: DEMONSTRATED

Primary entities:

McDonald'sMcHire AI hiring toolData LeakageMcDonaldpii

Timeline

  • Incident first seen
    Jul 11, 2025 05:30

    BugSkan first recorded this incident.

  • McDonald’s AI hiring tool’s password ‘123456’ exposed data of 64M applicants - csoonline.com
    Jul 11, 2025 05:30

    csoonline.com ¡ Data Leak

Sources

McDonald’s AI hiring tool’s password ‘123456’ exposed data of 64M applicants - csoonline.com

csoonline.com ¡ Jul 11, 2025 05:30

A critical security flaw in McDonald's McHire AI hiring tool leveraged default '123456' administrative credentials combined with an Insecure Direct Object Reference (IDOR) vulnerability in an internal API. This exploit allowed researchers to access and potentially expose sensitive Personally Identifiable Information (PII) for millions of job applicants, including chat histories and contact details.

Open publisher source

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence