• Latest
  • Trending
  • All
  • News
  • Business
  • Politics
  • Science
  • World
  • Lifestyle
  • Tech
A ‘high severity’ TikTok vulnerability allowed one-click account hijacking

A ‘high severity’ TikTok vulnerability allowed one-click account hijacking

August 31, 2022
Home favourite Christie, South Korea’s An win Indonesia titles

Home favourite Christie, South Korea’s An win Indonesia titles

January 29, 2023
Gay And Trans People Who Have Been To Conversion Therapy Are Sharing Their Traumatic Stories, And It’s A Reminder Why It Needs To Be Abolished

Gay And Trans People Who Have Been To Conversion Therapy Are Sharing Their Traumatic Stories, And It’s A Reminder Why It Needs To Be Abolished

January 29, 2023
Miami Heat Aim For Fourth Win, Maintain Mastery Of Charlotte Hornets

Miami Heat Aim For Fourth Win, Maintain Mastery Of Charlotte Hornets

January 29, 2023
Nikki Haley Takes Swipe at Donald Trump As He Holds Rally in Her Home State

Nikki Haley Takes Swipe at Donald Trump As He Holds Rally in Her Home State

January 29, 2023
What it’s like to take Ozempic or Wegovy for weight loss or diabetes

What it’s like to take Ozempic or Wegovy for weight loss or diabetes

January 29, 2023
Netanyahu given Israelis ‘green light to shoot at Palestinians’

Netanyahu given Israelis ‘green light to shoot at Palestinians’

January 29, 2023
Video of Tyre Nichols ‘living his best life’ goes viral after he’s fatally beaten by Memphis cops

Video of Tyre Nichols ‘living his best life’ goes viral after he’s fatally beaten by Memphis cops

January 29, 2023
Palestinian Man Fatally Shot as Violence Continues With Israel Forces

Palestinian Man Fatally Shot as Violence Continues With Israeli Forces

January 29, 2023
Husband of Mom Who Strangled Three Kids: I Forgive Her

Husband of Mom Who Strangled Three Kids: I Forgive Her

January 29, 2023
Raising retirement age to 64 ‘is now non-negotiable’ says French PM Borne as strikes loom

Raising retirement age to 64 ‘is now non-negotiable’ says French PM Borne as strikes loom

January 29, 2023
Are the French People Just Lazy?

Are French People Just Lazy?

January 29, 2023
Have The Eagles Won A Super Bowl? Philadelphia’s Championship History

Have The Eagles Won A Super Bowl? Philadelphia’s Championship History

January 29, 2023
DNYUZ
  • Home
  • News
    • U.S.
    • World
    • Politics
    • Opinion
    • Business
    • Crime
    • Education
    • Environment
    • Science
  • Entertainment
    • Culture
    • Music
    • Movie
    • Television
    • Theater
    • Gaming
    • Sports
  • Tech
    • Apps
    • Autos
    • Gear
    • Mobile
    • Startup
  • Lifestyle
    • Arts
    • Fashion
    • Food
    • Health
    • Travel
No Result
View All Result
DNYUZ
No Result
View All Result
Home Tech Apps

A ‘high severity’ TikTok vulnerability allowed one-click account hijacking

August 31, 2022
in Apps, News, Tech
A ‘high severity’ TikTok vulnerability allowed one-click account hijacking
515
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

A vulnerability in the TikTok app for Android could have let attackers take over any account that clicked on a malicious link, potentially affecting hundreds of millions of users of the platform.

Details of the one-click exploit were revealed today in a blog post from researchers on Microsoft’s 365 Defender Research Team. The vulnerability was disclosed to TikTok by Microsoft, and has since been patched.

The bug and its resulting attack, labelled a “high severity vulnerability,” could have been used to hijack the account of any TikTok user on Android without their knowledge, once they clicked on a specially crafted link. After the link was clicked, the attacker would have access to all primary functions of the account, including the ability to upload and post videos, send messages to other users, and view private videos stored in the account.

The potential impact was huge, as it affected all global variants of the Android TikTok app, which has a total of more than 1.5 billion downloads on the Google Play Store. However, there’s no evidence it was exploited at scale. Researchers involved with the discovery and disclosure praised TikTok for a quick response.

“We gave them information about the vulnerability and collaborated to help fix this issue” Tanmay Ganacharya, partner director for security research at Microsoft Defender for Endpoint, told The Verge. “TikTok responded quickly, and we commend the the efficient and professional resolution from the security team.”

According to details published in the blog post, the vulnerability affected the deep link functionality of the Android app. This deep link handling tells the operating system to let certain apps process links in a specific way, such as opening the Twitter app to follow a user after clicking an HTML “Follow this account” button embedded in a webpage.

This link handling also includes a verification process that should restrict the actions performed when an application loads a given link. But the researchers found a way to bypass this verification process and execute a number of potentially weaponizable functions within the app.

One of these functions let them retrieve an authentication token tied to a certain user account, effectively granting account access without the need to enter a password. In a proof-of-concept attack, the researchers crafted a malicious link that, when clicked, changed a TikTok account’s bio to read “SECURITY BREACH.”

Fortunately, the vulnerability was detected, and Microsoft has used the opportunity to stress the importance of collaboration and coordination between technology platforms and vendors.

“As threats across platforms continue to grow in numbers and sophistication, vulnerability disclosures, coordinated response, and other forms of threat intelligence sharing are needed to help secure users’ computing experience, regardless of the platform or device in use,” wrote Microsoft’s Dimitrios Valsamaras in the blog post. “We will continue to work with the larger security community to share research and intelligence about threats in the effort to build better protection for all.”

Although the TikTok app is not known to have suffered any major hacks so far, some critics have branded it a security risk for other reasons.

Recently, concerns have been raised over the extent to which US users’ data can be accessed by China-based engineers at ByteDance, TikTok’s parent company. In July, Senate Intelligence Committee leaders called on FTC chair Lina Khan to investigate TikTok after reports brought into question claims that US users’ data was walled off from the Chinese branch of the company.

TikTok had not responded to questions from The Verge by time of publication.

The post A ‘high severity’ TikTok vulnerability allowed one-click account hijacking appeared first on The Verge.

Tags: AppsPolicyTech
Share206Tweet129Share

Trending Posts

Rhode Island school collects donations to pay cartel ‘coyote’ who brought boy to US: emails

Rhode Island school collects donations to pay cartel ‘coyote’ who brought boy to US: emails

January 29, 2023
The Week in Business: Creeping Layoffs

The Week in Business: Creeping Layoffs

January 29, 2023
Your January 30, 2023 Weekly Horoscope Has Main Character Energy

Your January 30, 2023 Weekly Horoscope Has Main Character Energy

January 29, 2023
Ghislaine Maxwell’s claim that Prince Andrew-Virginia Giuffre pic is fake is ‘ridiculous’: report

Ghislaine Maxwell’s claim that Prince Andrew-Virginia Giuffre pic is fake is ‘ridiculous’: report

January 29, 2023
Russia Loses 8 Tanks, 22 APVs and 7 Artillery Systems in a Day: Ukraine

Russia Loses 8 Tanks, 22 APVs and 7 Artillery Systems in a Day: Ukraine

January 29, 2023

Copyright © 2023.

Site Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

No Result
View All Result
  • Home
  • News
    • U.S.
    • World
    • Politics
    • Opinion
    • Business
    • Crime
    • Education
    • Environment
    • Science
  • Entertainment
    • Culture
    • Gaming
    • Music
    • Movie
    • Sports
    • Television
    • Theater
  • Tech
    • Apps
    • Autos
    • Gear
    • Mobile
    • Startup
  • Lifestyle
    • Arts
    • Fashion
    • Food
    • Health
    • Travel

Copyright © 2023.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT