TikTok Flaw Allows Hackers to Put Fake Videos on Your Account: Report

Two developers showcased the problem by replacing WHO's TikTok video with a fake video.

Advertisement
By Abhik Sengupta | Updated: 15 April 2020 17:13 IST
Highlights
  • TikTok flaw was exposed by two iOS developers in a blog post
  • Developers said TikTok's CDN delivers files via unencrypted HTTP
  • This can expose TikTok users' watch history and more

TikTok recently surpassed one billion installs on the Google Play Store

Popular short video sharing platform TikTok has been called out by two developers who claim that the company uses an insecure network to deliver bulk of the data, thereby, risking the privacy of the users on its platform. According to the two iOS developers, TikTok allegedly uses "insecure HTTP to download media content," that "puts user privacy at risk" since unencrypted HTTP traffic can be easily tracked and even altered by malicious actors. This means users' data including their watch history can be accessed by hackers. Meanwhile, TikTok is yet to respond to the 'security threat' exposed by the developers. The company's app recently surpassed one billion installs on the Google Play Store.

The developers, Talal Haj Bakry and Tommy Mysk, in a blog post highlighted that due to usage of insecure HTTP, hackers can also "switch videos published by TikTok users with different ones, including those from verified accounts." The duo further claimed this vulnerability can also expose user's watch history.

While explaining why the security threat exists, the developers in the blog post stated that TikTok like another social media outlet relies on external servers or Content Delivery Networks (CDNs) to deliver bulk of its data. The post added that TikTok's CDN further chooses to transfer videos and other media data over unencrypted HTTP.

Advertisement

"While this [HTTP] improves the performance of data transfer, it puts user privacy at risk. HTTP traffic can be easily tracked, and even altered by malicious actors," the developers wrote.

Advertisement

This essentially means that anyone who can see the network traffic passing through a Wi-Fi router could read information coming from TikTok's servers and modify it by even planting a fake video in an account without user's knowledge.

According to the blog post, files such as "videos, profile photos, and video still images" are transferred via HTTP, indicating they are at risk of being accessed by hackers. To further showcase the vulnerability of the TikTok app, Bakry and Mysk posted videos on their blog where they intercepted the data from CDN servers and replaced with "malicious content". The video, therefore, showed fake COVID-19 related content on WHO's TikTok account, which was planted by them.

Advertisement

"We successfully intercepted TikTok traffic and fooled the app to show our own videos as if they were published by popular and verified accounts. This makes a perfect tool for those who relentlessly try to pollute the Internet with misleading facts," the developers said.

However, the duo cautioned that this "malicious content" was only seen by those who were connected to their servers. The developers indicated that exposed threat, when replicated on a large scale server, can post greater privacy or fake-news related risks. They further added the vulnerability is present on TikTok's iOS version 15.5.6 and Android version 15.7.4.

Advertisement

Meanwhile, TikTok is yet to address the concerns raised by the two developers. TikTok recently surpassed a billion downloads on Google Play. This was amid lockdowns in several countries to curb the spread of novel coronavirus.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: TikTok, TikTok flaw, Data Privacy
Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  2. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  3. Apple Allows Third-Party App Stores, Relaxes Payment Restrictions in Japan
  4. Samsung's 2nm Exynos 2600 Details Leak With 10-Core CPU and AMD GPU
  5. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  6. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  7. Samsung Announces Exynos 2600 as World's First 2nm Chipset
  8. Truecaller's Voicemail Feature Is Now Free for Android Users in India
  1. Instagram Announces a Five-Hashtag Limit for Reels and Posts to Improve Content Discovery
  2. Samsung Announces Exynos 2600 as World’s First 2nm Node Chipset for Flagship Galaxy Devices
  3. Physicists Push Superconducting Diodes to Higher Temperatures
  4. NASA’s Perseverance Rover Poised for Years of Exploration Across Jezero Crater
  5. James Webb Space Telescope Could Illuminate Dark Matter in an Unexpected Way
  6. James Webb Confirms First Runaway Supermassive Black Hole Rocking Through Space
  7. Interstellar Comet 3I/ATLAS to Make Closest Approach to Earth on December 19
  8. The Roofman Now Streaming Online: Everything You Need to Know
  9. Adobe Firefly Platform Updated With New AI Models and Tools, Offers Limited-Time Unlimited Generations
  10. Boat Valour Ring 1 Launched in India With Heart Rate Variability Tracking, Up to 15-Day Battery Life: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.