Home Tech A basic security flaw let a security researcher access internal FIFA systems...

A basic security flaw let a security researcher access internal FIFA systems — and the ability to control World Cup TV streams

11
0
A basic security flaw let a security researcher access internal FIFA systems — and the ability to control World Cup TV streams

  • Researcher “BobDaHacker” found FIFA API flaw letting anyone hijack live TV streams and commentator feeds
  • Bug stemmed from lack of authorization checks; FIFA patched quickly but did not credit the finder
  • Experts warn it highlights CWE‑602 and the danger of confusing authentication with authorization

A bug in an internal FIFA system allowed anyone to modify what gets streamed to TV broadcasters, and what goes to TV commentators narrating the FIFA 2026 World Cup matches. Luckily for everyone, the bug was discovered by a white hat hacker and remedied before any malicious actors could leverage it.

Asecurity researcher with the alias BobDaHacker recently reported being able to take full control over the TV stream. They did it by registering as a player agent of FIFA’s official agent registration platform and then abusing a vulnerability in FIFA’s back-end API to access multiple internal platforms.

LEAVE A REPLY

Please enter your comment!
Please enter your name here