TikTok Flaw Allows Hackers to Put Fake Videos on Your Account: Report

Two developers showcased the problem by replacing WHO's TikTok video with a fake video.

Advertisement
By Abhik Sengupta | Updated: 15 April 2020 17:13 IST
Highlights
  • TikTok flaw was exposed by two iOS developers in a blog post
  • Developers said TikTok's CDN delivers files via unencrypted HTTP
  • This can expose TikTok users' watch history and more

TikTok recently surpassed one billion installs on the Google Play Store

Popular short video sharing platform TikTok has been called out by two developers who claim that the company uses an insecure network to deliver bulk of the data, thereby, risking the privacy of the users on its platform. According to the two iOS developers, TikTok allegedly uses "insecure HTTP to download media content," that "puts user privacy at risk" since unencrypted HTTP traffic can be easily tracked and even altered by malicious actors. This means users' data including their watch history can be accessed by hackers. Meanwhile, TikTok is yet to respond to the 'security threat' exposed by the developers. The company's app recently surpassed one billion installs on the Google Play Store.

The developers, Talal Haj Bakry and Tommy Mysk, in a blog post highlighted that due to usage of insecure HTTP, hackers can also "switch videos published by TikTok users with different ones, including those from verified accounts." The duo further claimed this vulnerability can also expose user's watch history.

While explaining why the security threat exists, the developers in the blog post stated that TikTok like another social media outlet relies on external servers or Content Delivery Networks (CDNs) to deliver bulk of its data. The post added that TikTok's CDN further chooses to transfer videos and other media data over unencrypted HTTP.

Advertisement

"While this [HTTP] improves the performance of data transfer, it puts user privacy at risk. HTTP traffic can be easily tracked, and even altered by malicious actors," the developers wrote.

Advertisement

This essentially means that anyone who can see the network traffic passing through a Wi-Fi router could read information coming from TikTok's servers and modify it by even planting a fake video in an account without user's knowledge.

According to the blog post, files such as "videos, profile photos, and video still images" are transferred via HTTP, indicating they are at risk of being accessed by hackers. To further showcase the vulnerability of the TikTok app, Bakry and Mysk posted videos on their blog where they intercepted the data from CDN servers and replaced with "malicious content". The video, therefore, showed fake COVID-19 related content on WHO's TikTok account, which was planted by them.

Advertisement

"We successfully intercepted TikTok traffic and fooled the app to show our own videos as if they were published by popular and verified accounts. This makes a perfect tool for those who relentlessly try to pollute the Internet with misleading facts," the developers said.

However, the duo cautioned that this "malicious content" was only seen by those who were connected to their servers. The developers indicated that exposed threat, when replicated on a large scale server, can post greater privacy or fake-news related risks. They further added the vulnerability is present on TikTok's iOS version 15.5.6 and Android version 15.7.4.

Advertisement

Meanwhile, TikTok is yet to address the concerns raised by the two developers. TikTok recently surpassed a billion downloads on Google Play. This was amid lockdowns in several countries to curb the spread of novel coronavirus.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: TikTok, TikTok flaw, Data Privacy
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Feb 16 - Feb 22): Know What to Watch This Weekend
  2. Realme P4 Lite With 6,300mAh Battery Launched at This Price in India
  3. Poco X8 Pro Series Display, Chipset, Battery Details Leak Online
  4. Vivo V70 Elite, V70 Launched in India With 6,500mAh Batteries: See Prices
  5. Samsung Galaxy A37, Galaxy A57 India Launch Timeline, Specifications Tipped; Spotted on IM
  6. WhatsApp's New Feature Allows New Members to View Past Group Messages
  7. Nothing Confirms the Upcoming Phone 4a Series Will Sport a Snapdragon Chip
  8. Amazfit T-Rex Ultra 2 With BioTracker 6.0 Sensor Launched at This Price
  1. Google Chrome Updated With Split View, Built-In PDF Markup Tools, and More Features
  2. Realme P4 Lite Launched in India With 6,300mAh Battery, 13-Megapixel Camera: Price, Specifications
  3. Samsung Galaxy Buds 4 Leak Again as Dummy Units Surface Online: Expected Price, Features
  4. Sony to Shut Down Demon's Souls Remake Developer Bluepoint Games in March
  5. Amazfit T-Rex Ultra 2 Launched With BioTracker 6.0 Sensor, 1.5-Inch AMOLED Display
  6. iPhone Air User Complains of C1X Modem Failure, Claims Mobile Diagnostics Suggests Hardware Issue
  7. Redmi Buds 8 Active Price, Design, Key Features Leaked Ahead of Anticipated Launch
  8. Samsung's One UI 8.5 Update Will Introduce Upgraded Bixby With Natural Voice Commands, Real-Time Web Access
  9. Poco X8 Pro and Poco X8 Pro Max to Feature 1.5K OLED Screens, 100W Charging Support, Tipster Claims
  10. WhatsApp Rolls Out Group Message History Feature for Easy Onboarding of New Members
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.