TikTok Flaw Allows Hackers to Put Fake Videos on Your Account: Report

Two developers showcased the problem by replacing WHO's TikTok video with a fake video.

Advertisement
By Abhik Sengupta | Updated: 15 April 2020 17:13 IST
Highlights
  • TikTok flaw was exposed by two iOS developers in a blog post
  • Developers said TikTok's CDN delivers files via unencrypted HTTP
  • This can expose TikTok users' watch history and more
TikTok Flaw Allows Hackers to Put Fake Videos on Your Account: Report

TikTok recently surpassed one billion installs on the Google Play Store

Popular short video sharing platform TikTok has been called out by two developers who claim that the company uses an insecure network to deliver bulk of the data, thereby, risking the privacy of the users on its platform. According to the two iOS developers, TikTok allegedly uses "insecure HTTP to download media content," that "puts user privacy at risk" since unencrypted HTTP traffic can be easily tracked and even altered by malicious actors. This means users' data including their watch history can be accessed by hackers. Meanwhile, TikTok is yet to respond to the 'security threat' exposed by the developers. The company's app recently surpassed one billion installs on the Google Play Store.

The developers, Talal Haj Bakry and Tommy Mysk, in a blog post highlighted that due to usage of insecure HTTP, hackers can also "switch videos published by TikTok users with different ones, including those from verified accounts." The duo further claimed this vulnerability can also expose user's watch history.

While explaining why the security threat exists, the developers in the blog post stated that TikTok like another social media outlet relies on external servers or Content Delivery Networks (CDNs) to deliver bulk of its data. The post added that TikTok's CDN further chooses to transfer videos and other media data over unencrypted HTTP.

"While this [HTTP] improves the performance of data transfer, it puts user privacy at risk. HTTP traffic can be easily tracked, and even altered by malicious actors," the developers wrote.

Advertisement

This essentially means that anyone who can see the network traffic passing through a Wi-Fi router could read information coming from TikTok's servers and modify it by even planting a fake video in an account without user's knowledge.

According to the blog post, files such as "videos, profile photos, and video still images" are transferred via HTTP, indicating they are at risk of being accessed by hackers. To further showcase the vulnerability of the TikTok app, Bakry and Mysk posted videos on their blog where they intercepted the data from CDN servers and replaced with "malicious content". The video, therefore, showed fake COVID-19 related content on WHO's TikTok account, which was planted by them.

Advertisement

"We successfully intercepted TikTok traffic and fooled the app to show our own videos as if they were published by popular and verified accounts. This makes a perfect tool for those who relentlessly try to pollute the Internet with misleading facts," the developers said.

However, the duo cautioned that this "malicious content" was only seen by those who were connected to their servers. The developers indicated that exposed threat, when replicated on a large scale server, can post greater privacy or fake-news related risks. They further added the vulnerability is present on TikTok's iOS version 15.5.6 and Android version 15.7.4.

Advertisement

Meanwhile, TikTok is yet to address the concerns raised by the two developers. TikTok recently surpassed a billion downloads on Google Play. This was amid lockdowns in several countries to curb the spread of novel coronavirus.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: TikTok, TikTok flaw, Data Privacy
Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 16 Pro, iPhone 16 Pro Max Price Discounted on Flipkart: See Offers
  2. Adobe Launches a New Camera App for iPhone With Full Manual Controls
  3. Nothing Headphone 1 Renders Leaked Ahead of July 1 Launch: See Design
  4. Vivo Y400 Pro 5G With 5,500mAh Battery Launched in India: Price, Features
  1. Samsung Galaxy S24 FE Gets a Price Cut on Amazon: See Offer
  2. Samsung Galaxy Buds Core Listed on Company Site; Design, Specifications Revealed
  3. iPhone 18 Pro Series Tipped to Get Hole-Punch Selfie Camera, Hidden Face ID System
  4. iPhone 16 Pro, iPhone 16 Pro Max Available at Discounted Prices on Flipkart: See Offers
  5. Oppo Reno 14 5G Series Global Launch Date Announced; Amazon, Flipkart Tease Online Availability in India
  6. Gigabyte Aorus Master 16 AI PC With Intel Core Ultra 9 Chip, Up to GeForce RTX 5080 GPU Launched in India
  7. Google Suffers Setback in Fight Over EU’s EUR 4.1 Billion Fine
  8. Vivo X Fold 5 India Launch Reportedly Set for Mid-July
  9. Trump Extends Deadline for US TikTok Sale to September
  10. Nothing Headphone 1 Renders and Live Images Leak Ahead of July 1 Launch; Shows Unique Design
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.