Internet related News · 2022-09-01

Vulnerability in TikTok Android app could lead to one-click account hijacking: Microsoft – News

Microsoft has discovered a “high-severity” vulnerability in the TikTok Android application, which could have allowed attackers to compromise users’ accounts with a single click. The vulnerability, which would have required several issues to be chained together to exploit, has been fixed, said Microsoft.

Attackers could have leveraged the vulnerability to hijack an account without users’ awareness if a targeted user simply clicked a specially crafted link. Attackers could have then accessed & modified users’ TikTok profiles & sensitive information, such as by publicizing private videos, sending messages, & uploading videos on behalf of users.

Microsoft said the vulnerability allowed the app’s deeplink verification to be bypassed. Attackers could force the app to load an arbitrary URL to the app’s WebView, allowing the URL to then access the WebView’s attached JavaScript bridges & grant functionality to attackers.

Click here to opt-out of Google Analytics