TikTok Vulnerabilities Could Allow Account Takeover by Hackers, More: All You Need to Know

TikTok security flaw found by Check Point Research has now been fixed. Users are recommended to update to the latest app versions as a precaution.

Advertisement
By Nadeem Sarwar | Updated: 9 January 2020 17:28 IST
Highlights
  • TikTok users could be tricked by SMS spoofing into losing account control
  • Hackers could do damages like deleting clips or exposing sensitive data
  • A TikTok sub-domain was also found to be vulnerable to XSS attacks

TikTok user data was under threat, but thankfully, the company has fixed the flaws

TikTok has been in the news lately for all the wrong reasons. Take for example the ban imposed by US Army, preventing soldiers from using the viral app on government-issued phones citing security concerns. Now, Check Point research has reported multiple vulnerabilities in the TikTok app that could allow hackers to gain control of a user account and manipulate its content, erase videos, change the privacy status, and do a lot more damage. Thankfully, the vulnerabilities in TikTok have now been fixed. While most of the fixes were on the back-end, users are recommended to update their apps to the latest version to be on the safe side.

Check Point Research mentions in its blog post that it was possible to send an SMS message to a mobile number on behalf of TikTok. This functionality is available on the official TikTok website to let users download the app. However, hackers can capture HTTP request using a proxy tool and spoof a message that can contain any harmful link the malicious party intends to send. The link in question can then redirect users to a malicious website, and this was made possible because the redirection process was found to be vulnerable. This further opens the possibility of launching Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Sensitive Data Exposure attacks. 

Advertisement

Once this happens, the attacker can take advantage of multiple intermediary techniques to become a follower of the victim and wreak havoc. The possible damage scenarios include deleting someone's TikTok videos, upload unauthorised clips, make ‘private' videos public, and even expose sensitive personal information associated with a TikTok account such as the linked email address, birth dates, payment details, and more. It is essentially equivalent to having a complete account takeover. Thankfully, Check Point Research notified TikTok about the vulnerability and the flaw was fixed before the findings were made public.

The security experts at Check Point Research also discovered that a TikTok subdomain (https://ads.tiktok.com) was vulnerable to XSS attacks, which could allow hackers to inject malicious scripts in trusted websites. In the case of TikTok, the injection point for launching an XSS attack was found in the search functionality. The Check Point Research blog post also notes that TikTok employed an unconventional JSONP callback that makes it possible to request data from API servers without CORS and SOP restrictions, which made it possible to steal data by initiating an AJAX request. 

Advertisement

“TikTok is committed to protecting user data. Like many organisations, we encourage responsible security researchers to privately disclose zero day vulnerabilities to us. Before public disclosure, CheckPoint agreed that all reported issues were patched in the latest version of our app. We hope that this successful resolution will encourage future collaboration with security researchers,” Luke Deshotels from TikTok Security Team's was quoted as saying in Check Point Research' press release.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Poco F9 Ultra, Poco F9 Pro Spotted on Multiple Certification Sites Ahead of Launch
  2. Here's How the Oppo Find X10 Series Could Look
  3. Snapdragon 8 Elite Gen 5 Could Get Another Variant, Tipster Claims
  4. Apple to Become Third-Largest Foldable Phone Maker Within Months of Launch
  5. Vivo S2 Price in India, Storage Variants Leaked Ahead of Rumoured Launch
  6. Xiaomi Power Bank 5i 20000 67W With Built-In USB Type-C Cable Launched in India
  7. New OTT Releases This Week: Musafir Cafe, Adarsh Baal Vidyalaya, and More
  8. Apple Rolls Out iOS 27 Public Beta 2 Update for Eligible iPhone Models
  9. Oppo K15 With Dual 50-Megapixel Rear Cameras Arrives at This Price
  10. iQOO 15 Ultra Appears on EEC Listing Ahead of Global Launch
  1. iPhone 18 Pro Max Could Be Apple's Most Expensive Non-Folding iPhone Yet, Leak Suggests
  2. iQOO 15 Ultra Global Variant Reportedly Spotted on EEC Certification Site
  3. Oppo K15 Launched With 8,000mAh Battery, Dual 50-Megapixel Rear Cameras: Price, Specifications
  4. iPhone Ultra to Challenge Samsung, Huawei With 25 Percent Market Share Within Months of Launch: Report
  5. Qualcomm Reportedly Developing Fourth Snapdragon 8 Elite Gen 5 Variant for More Affordable Flagship Phones
  6. Apple Rolls Out iOS 27 Public Beta 2 Update for Eligible iPhone Models: See What’s New
  7. Samsung Galaxy Z Fold 9 Ultra May Match Galaxy S27 Ultra With 200-Megapixel Camera, 5x Periscope Zoom
  8. Google Introduces Selfie Video Sign-In for Account Recovery
  9. Boat Nirvana Eutopia 2 ANC Launched in India With 45dB Hybrid ANC, Up to 80 Hours of Battery Life: Price, Features
  10. WhatsApp Could Replace Two-Step Verification PIN With a Stronger Password
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.