Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

TikTok denies security breach after hackers claim to have records of more than a billion users

Welcome back

Microsoft found a severe one-click exploit in TikTok’s Android app

Thankfully, TikTok patched the vulnerability.

Igor Bonifacic
I. Bonifacic
 
TikTok denies security breach after hackers claim to have records of more than a billion users
NurPhoto via Getty Images

A serious vulnerability found by Microsoft in the TikTok Android app could have allowed hackers to hijack millions of accounts. On Wednesday, the company’s 365 Defender Research Team detailed a one-click exploit it informed TikTok of in February. The good news is that the social media company promptly patched the vulnerability before today’s disclosure and Microsoft says it has no evidence of someone using it out in the wild.

“We gave them information about the vulnerability and collaborated to help fix this issue,” Microsoft’s Tanmay Ganacharya told The Verge. “TikTok responded quickly, and we commend the efficient and professional resolution from the security team.”

According to Microsoft, the vulnerability involved an oversight with TikTok’s deep linking functionality. On Android, developers can program their apps to handle certain URLs in specific ways. For instance, when you tap on a Twitter embed in Chrome and the Twitter app automatically opens on your phone as a result, that’s an example of the deep linking feature working as intended.

 

However, Microsoft found a way to bypass the verification process TikTok had in place to restrict deep links from executing certain actions. They then discovered they could use that vulnerability to access all the primary functions of an account, including the ability to post content and message other TikTok users. The flaw was present in both global versions of TikTok’s Android app. The two releases have more than 1.5 billion downloads between them, meaning the potential impact of someone discovering the vulnerability before it was patched could have been massive.

Microsoft recommends all TikTok users on Android download the latest version of the app as soon as they can. More broadly, you can protect yourself in the future from similar exploits by not clicking on sketchy links. It’s also good practice to avoid sideloading apps as you don’t know how someone could have altered the APK.

Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics   

(15)

Report Post