
A security researcher discovered a vulnerability in FIFA's systems, enabling her to control the TV stream of World Cup games by exploiting a flaw in the registration process.
A security researcher identified a vulnerability within FIFA's online platforms that permitted her to access multiple internal systems, including the ability to watch and control the TV stream of every World Cup match.


The researcher, known as BobDaHacker, explained that she was able to exploit this flaw by registering as a player agent on FIFA's official agent registration platform. The issue stemmed from a weakness in FIFA's back-end API, which failed to verify whether a user had the necessary authorization to access certain internal systems.
Among the platforms BobDaHacker accessed was the system that enables broadcasters to manage what is displayed on viewers' televisions worldwide, as well as the information shown on commentators' screens during the matches.
"A single attacker could hijack every camera simultaneously. An attacker could have rickrolled the entire FIFA World Cup," BobDaHacker remarked in a blog post published on Tuesday.
The researcher reported the security flaw on Tuesday night, Japan time, and FIFA responded by fixing the issue within a few hours. However, the organization did not acknowledge the researcher’s report.
TechCrunch reached out to FIFA for comments regarding the incident but did not receive an immediate response.



