• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

Supermouth Ultim8 electric toothbrush review: Gentle giant

August 20, 2025

Samsung Galaxy Watch 8 Review: A solid albeit unexciting smartwatch

August 19, 2025

Huawei MatePad 11.5 review: iPad rival that’s missing a trick

August 17, 2025
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Security»A ‘high severity’ TikTok vulnerability allowed one-click account hijacking
Security

A ‘high severity’ TikTok vulnerability allowed one-click account hijacking

August 31, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
A ‘high severity’ TikTok vulnerability allowed one-click account hijacking
Share
Facebook Twitter LinkedIn Pinterest Email

A vulnerability within the TikTok app for Android might have let attackers take over any account that clicked on a malicious hyperlink, doubtlessly affecting tons of of hundreds of thousands of customers of the platform.

Particulars of the one-click exploit had been revealed at present in a blog post from researchers on Microsoft’s 365 Defender Analysis Staff. The vulnerability was disclosed to TikTok by Microsoft, and has since been patched.

The bug and its ensuing assault, labelled a “excessive severity vulnerability,” might have been used to hijack the account of any TikTok consumer on Android with out their data, as soon as they clicked on a specifically crafted hyperlink. After the hyperlink was clicked, the attacker would have entry to all main features of the account, together with the flexibility to add and put up movies, ship messages to different customers, and look at non-public movies saved within the account.

The potential impression was big, because it affected all international variants of the Android TikTok app, which has a complete of greater than 1.5 billion downloads on the Google Play Retailer. Nevertheless, there’s no proof it was exploited at scale. Researchers concerned with the invention and disclosure praised TikTok for a fast response.

“We gave them details about the vulnerability and collaborated to assist repair this challenge” Tanmay Ganacharya, associate director for safety analysis at Microsoft Defender for Endpoint, advised The Verge. “TikTok responded shortly, and we commend the the environment friendly {and professional} decision from the safety workforce.”

Based on particulars printed within the weblog put up, the vulnerability affected the deep link performance of the Android app. This deep hyperlink dealing with tells the working system to let sure apps course of hyperlinks in a selected approach, comparable to opening the Twitter app to comply with a consumer after clicking an HTML “Observe this account” button embedded in a webpage.

See also  What is a cyberattack surface and how can you reduce it?

This hyperlink dealing with additionally features a verification course of that ought to prohibit the actions carried out when an utility masses a given hyperlink. However the researchers discovered a approach to bypass this verification course of and execute quite a lot of doubtlessly weaponizable features inside the app.

One among these features allow them to retrieve an authentication token tied to a sure consumer account, successfully granting account entry with out the necessity to enter a password. In a proof-of-concept assault, the researchers crafted a malicious hyperlink that, when clicked, modified a TikTok account’s bio to learn “SECURITY BREACH.”

A screenshot of a compromised account.
Microsoft

Fortuitously, the vulnerability was detected, and Microsoft has used the chance to emphasize the significance of collaboration and coordination between know-how platforms and distributors.

“As threats throughout platforms proceed to develop in numbers and class, vulnerability disclosures, coordinated response, and different types of risk intelligence sharing are wanted to assist safe customers’ computing expertise, whatever the platform or machine in use,” wrote Microsoft’s Dimitrios Valsamaras within the weblog put up. “We are going to proceed to work with the bigger safety group to share analysis and intelligence about threats within the effort to construct higher safety for all.”

Though the TikTok app just isn’t identified to have suffered any main hacks to date, some critics have branded it a safety threat for different causes.

Just lately, considerations have been raised over the extent to which US customers’ knowledge could be accessed by China-based engineers at ByteDance, TikTok’s guardian firm. In July, Senate Intelligence Committee leaders referred to as on FTC chair Lina Khan to analyze TikTok after reviews introduced into query claims that US customers’ knowledge was walled off from the Chinese language department of the corporate.

TikTok had not responded to questions from The Verge by time of publication.

Source link

account Allowed high hijacking oneclick severity TikTok Vulnerability
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Would You Pay $2,000 a Week to Get Your Kid off TikTok?

July 22, 2025

TikTok Plans Special US App as It Looks to Stay In the Game

July 8, 2025

TikTok Gets Yet Another Reprieve from President Trump

June 20, 2025

Secure Your iCloud Account After Big Password Leak

May 22, 2025
Add A Comment

Comments are closed.

Editors Picks

Three customer centric leadership lessons for pioneering financial services brands

December 11, 2022

Fortnite x Magic: The Gathering crossover cards announced

July 10, 2022

‘Inventions We Love’ will showcase four Seattle startup innovations at Startup Summit – Startup

October 2, 2022

Business Really Picking Up During The Holidays? Eight Tips For Workload Management

December 19, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Supermouth Ultim8 electric toothbrush review: Gentle giant

Samsung Galaxy Watch 8 Review: A solid albeit unexciting smartwatch

Huawei MatePad 11.5 review: iPad rival that’s missing a trick

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.