Back to Database
Status published
Medium
CVE-2025-62646
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows...
Vulnerability Description
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62646
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.yahoo.com/news/articles/burger-king-hacked-attackers-impressed-124154038.html
- https://www.malwarebytes.com/blog/news/2025/09/popeyes-tim-hortons-burger-king-platforms-have-catastrophic-vulnerabilities-say-hackers
- https://web.archive.org/web/20250906134240/https:/bobdahacker.com/blog/rbi-hacked-drive-thrus
- https://bobdahacker.com/blog/rbi-hacked-drive-thrus/
- https://archive.today/fMYQp
More from Restaurant Brands International
View All →CVE-2025-62651
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does...
Medium
6.5
CVE-2025-62650
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies...
High
8.3
CVE-2025-62649
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies...
Medium
5.8
CVE-2025-62648
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows...
Medium
6.4
CVE-2025-62647
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides...
Medium
5
Affected Vendor
Restaurant Brands International
View all reports →Affected Software
assistant platform
Vulnerable Versions:
0
Timeline
Official Publish:
October 17th, 2025
Last Modified:
October 29th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.