Category: General|Jan 12, 2020 | Author: Admin

Multiple TikTok Vulnerabilities Could Exploit Or Delete Users’ Personal Data

Share on

Social media craze TikTok has now made it to the news owing to security issues. Researchers have found numerous vulnerabilities in the TikTok app that could risk users’ security. Exploiting the bugs could allow an attacker to add or delete users’ videos or alter privacy settings.

Multiple TikTok Vulnerabilities Found Researchers from Check Point Research have found numerous vulnerabilities in the TikTok app.

The vulnerabilities could have serious security consequences if exploited by an adversary. Detailing their findings in a blog post, the researchers stated that numerous security flaws affected the app in different ways. In brief, a successful attack required a perpetrator to first use SMS spoofing to send malicious links to the target.

Clicking on the link would then exploit the ‘deep links’ functionality of Tiktok. This would subsequently allow the attacker to trigger an intent in the app via the browser URL.

Then, the malicious link would redirect the victim to a malicious website, opening the possibilities for cross-site scripting (XSS) attacks, cross-site request forgery (CSRF) attacks, and data exposure. Some possible attack scenarios include deletion of videos from users’ accounts, adding videos to the account, or making private videos public.

Moreover, the attacker could simply take control of the target account and gain access to the victim’s personal information. The following video demonstrates how an adversary could exploit all the flaws for a successful attack.

TikTok Patched The Flaws Check Point has confirmed that TikTok has addressed the issues after the researchers reported the matter to them. So for now, TikTok users can continue to use the app safely.

Let us know your thoughts in the comments.

Sponsored Ads:

Comments:


Only possible with VPN

Category: IT|Apr 22, 2024 | Author: Admin

Apple sidles into sideloading in the EU

Category: Apple|Apr 21, 2024 | Author: Admin

Report: Microsoft-OpenAI ownership might get conditional OK from EU regulators

Category: IT|Apr 20, 2024 | Author: Admin

Giant change at Google could change everything

Category: Google|Apr 19, 2024 | Author: Admin

Now Windows will be bothered about this too

Category: Microsoft|Apr 18, 2024 | Author: Admin

Test the new AI trick with Logitech

Category: IT|Apr 17, 2024 | Author: Admin

The US Government Has a Microsoft Problem

Category: Microsoft|Apr 16, 2024 | Author: Admin

Now comes the commercial

Category: Microsoft|Apr 15, 2024 | Author: Admin

Linux Foundation is leading fight against fauxpen source

Category: IT|Apr 14, 2024 | Author: Admin

3000 news articles!!! Happy reading!

Category: General|Apr 13, 2024 | Author: Admin

Google shuts down new product

Category: IT|Apr 12, 2024 | Author: Admin

YouTube CEO warns OpenAI that training models on its videos is against the rules

Category: IT|Apr 11, 2024 | Author: Admin

Google unveils Arm-based data center processor, new AI chip

Category: Google|Apr 10, 2024 | Author: Admin

Microsoft to invest $2.9 bln to expand AI, cloud infra in Japan

Category: Microsoft|Apr 9, 2024 | Author: Admin

Nintendo shuts off online access for 3DS and Wii U today

Category: IT|Apr 8, 2024 | Author: Admin
more