Category: General|Jan 12, 2020 | Author: Admin

Multiple TikTok Vulnerabilities Could Exploit Or Delete Users’ Personal Data

Share on

Social media craze TikTok has now made it to the news owing to security issues. Researchers have found numerous vulnerabilities in the TikTok app that could risk users’ security. Exploiting the bugs could allow an attacker to add or delete users’ videos or alter privacy settings.

Multiple TikTok Vulnerabilities Found Researchers from Check Point Research have found numerous vulnerabilities in the TikTok app.

The vulnerabilities could have serious security consequences if exploited by an adversary. Detailing their findings in a blog post, the researchers stated that numerous security flaws affected the app in different ways. In brief, a successful attack required a perpetrator to first use SMS spoofing to send malicious links to the target.

Clicking on the link would then exploit the ‘deep links’ functionality of Tiktok. This would subsequently allow the attacker to trigger an intent in the app via the browser URL.

Then, the malicious link would redirect the victim to a malicious website, opening the possibilities for cross-site scripting (XSS) attacks, cross-site request forgery (CSRF) attacks, and data exposure. Some possible attack scenarios include deletion of videos from users’ accounts, adding videos to the account, or making private videos public.

Moreover, the attacker could simply take control of the target account and gain access to the victim’s personal information. The following video demonstrates how an adversary could exploit all the flaws for a successful attack.

TikTok Patched The Flaws Check Point has confirmed that TikTok has addressed the issues after the researchers reported the matter to them. So for now, TikTok users can continue to use the app safely.

Let us know your thoughts in the comments.

Sponsored Ads:

Comments:


Does not have a single screw

Category: IT|Mar 29, 2023 | Author: Admin

If you do not switch to the new Windows, you will be denied Steam next year

Category: General|Mar 28, 2023 | Author: Admin

This may be the requirement for Windows 12

Category: Microsoft|Mar 27, 2023 | Author: Admin

Fixed the nasty Windows 11 privacy bug

Category: Microsoft|Mar 26, 2023 | Author: Admin

How to disable Bing button in Microsoft Edge?

Category: IT|Mar 25, 2023 | Author: Admin

This totally changes ChatGPT

Category: General|Mar 24, 2023 | Author: Admin

Fake ChatGPT stole Facebook accounts

Category: IT|Mar 23, 2023 | Author: Admin

New Apple products revealed

Category: Apple|Mar 22, 2023 | Author: Admin

OpenAI ChatGPT down! Users around the world unable to login and chat

Category: IT|Mar 21, 2023 | Author: Admin

Your disk may be much slower now

Category: General|Mar 20, 2023 | Author: Admin

Get complete price shock from this

Category: General|Mar 19, 2023 | Author: Admin

"iPhone 15 Pro Max breaks the record"

Category: Apple|Mar 18, 2023 | Author: Admin

Apple is testing a new generation

Category: Apple|Mar 17, 2023 | Author: Admin

"Here Microsoft pirates Windows 10"

Category: Microsoft|Mar 16, 2023 | Author: Admin

“Is built wrong”

Category: Apple|Mar 15, 2023 | Author: Admin
more