TikTok Flaw Allows Hackers to Put Fake Videos on Your Account: Report

Two developers showcased the problem by replacing WHO's TikTok video with a fake video.

Advertisement
By Abhik Sengupta | Updated: 15 April 2020 17:13 IST
Highlights
  • TikTok flaw was exposed by two iOS developers in a blog post
  • Developers said TikTok's CDN delivers files via unencrypted HTTP
  • This can expose TikTok users' watch history and more

TikTok recently surpassed one billion installs on the Google Play Store

Popular short video sharing platform TikTok has been called out by two developers who claim that the company uses an insecure network to deliver bulk of the data, thereby, risking the privacy of the users on its platform. According to the two iOS developers, TikTok allegedly uses "insecure HTTP to download media content," that "puts user privacy at risk" since unencrypted HTTP traffic can be easily tracked and even altered by malicious actors. This means users' data including their watch history can be accessed by hackers. Meanwhile, TikTok is yet to respond to the 'security threat' exposed by the developers. The company's app recently surpassed one billion installs on the Google Play Store.

The developers, Talal Haj Bakry and Tommy Mysk, in a blog post highlighted that due to usage of insecure HTTP, hackers can also "switch videos published by TikTok users with different ones, including those from verified accounts." The duo further claimed this vulnerability can also expose user's watch history.

While explaining why the security threat exists, the developers in the blog post stated that TikTok like another social media outlet relies on external servers or Content Delivery Networks (CDNs) to deliver bulk of its data. The post added that TikTok's CDN further chooses to transfer videos and other media data over unencrypted HTTP.

Advertisement

"While this [HTTP] improves the performance of data transfer, it puts user privacy at risk. HTTP traffic can be easily tracked, and even altered by malicious actors," the developers wrote.

Advertisement

This essentially means that anyone who can see the network traffic passing through a Wi-Fi router could read information coming from TikTok's servers and modify it by even planting a fake video in an account without user's knowledge.

According to the blog post, files such as "videos, profile photos, and video still images" are transferred via HTTP, indicating they are at risk of being accessed by hackers. To further showcase the vulnerability of the TikTok app, Bakry and Mysk posted videos on their blog where they intercepted the data from CDN servers and replaced with "malicious content". The video, therefore, showed fake COVID-19 related content on WHO's TikTok account, which was planted by them.

Advertisement

"We successfully intercepted TikTok traffic and fooled the app to show our own videos as if they were published by popular and verified accounts. This makes a perfect tool for those who relentlessly try to pollute the Internet with misleading facts," the developers said.

However, the duo cautioned that this "malicious content" was only seen by those who were connected to their servers. The developers indicated that exposed threat, when replicated on a large scale server, can post greater privacy or fake-news related risks. They further added the vulnerability is present on TikTok's iOS version 15.5.6 and Android version 15.7.4.

Advertisement

Meanwhile, TikTok is yet to address the concerns raised by the two developers. TikTok recently surpassed a billion downloads on Google Play. This was amid lockdowns in several countries to curb the spread of novel coronavirus.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: TikTok, TikTok flaw, Data Privacy
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Series Confirmed to Be Available in India via Flipkart
  2. Nothing Phone 3a Lite Launched With Glyph Light At This Price
  3. Amazon Fire TV Stick 4K Select Launched in India With Vega OS
  4. Oppo Find X9 Series With Hasselblad-Tuned Cameras Launched Globally
  5. Nothing Phone 3a Lite Launch Today: Everything You Need to Know
  6. Vivo X300 Series Price, Key Features Leaked Ahead of Global Launch
  7. TRAI, DoT Approve Presentation of Caller Names During Incoming Calls
  8. Moto G67 Power 5G India Launch Date, Key Features Announced
  9. OnePlus 15 Confirmed to Launch in India on This Date
  10. Ideabaaz Now Streaming on ZEE5: Everything You Need to Know
  1. Idli Kadai, Starring Dhanush, Now Streaming on Netflix: What You Need to Know
  2. Ideabaaz Now Streaming on ZEE5: Everything You Need to Know
  3. Grey’s Anatomy Season 22 OTT Release: Know Where to Watch it Online?
  4. Bad Girl OTT Release Date: When and Where to Watch Tamil Drama Online?
  5. Adobe Partners With Google Cloud to Integrate Frontier AI Models Across Its Platforms
  6. Vivo X300, Vivo X300 Pro Price and Key Specifications Leaked Ahead of Global Launch
  7. OnePlus 15 India Launch Date Announced; to Debut as First Snapdragon 8 Elite Gen 5 Phone in India
  8. Rangbaaz: The Bihar Chapter OTT Release Date: When and Where to Watch Crime Thriller Movie Online?
  9. French Lawmakers to Review Proposal to Ban CBDC, Support Bitcoin Reserve and Crypto Oversight
  10. Nothing Phone 3a Lite Launched With Essential Key, Glyph Light and 5,000mAh Battery: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.