Online Sales Guide Tips
+

Menu

Skip to content
  • Home
  • Our Services
    • Advertisement and Content Publishing
    • Contact Us to Publish
    • Sponsored Content
  • About
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    • About Us

Microsoft Identifies TikTok Vulnerability Allowing One-Click Account Hijacking

admin September 19, 2022TikTok Securityaccount, Allowing, Hijacking, Identifies, Microsoft, OneClick, TikTok, Vulnerabilityadmin


Microsoft Identifies TikTok Vulnerability Allowing One-Click Account Hijacking



by Laurie Sullivan , Staff Writer @lauriesullivan, August 31, 2022

Microsoft’s security team has found a vulnerability in the TikTok Android app.


The 365 Defender Research Team on Wednesday explained in a post how the one-click exploit could have allowed hackers to hijack millions of accounts.


“The vulnerability, which would have required several issues to be chained together to exploit, has been fixed and we did not locate any evidence of in-the-wild exploitation,” the company wrote in a blog post. “Attackers could have leveraged the vulnerability to hijack an account without users’ awareness if a targeted user simply clicked a specially crafted link.”


Attackers could have accessed and modified users’ TikTok profiles and sensitive information, such as by publicizing private videos, sending messages, and uploading videos on behalf of users, the company said.


Microsoft’s security team explains in the post that the vulnerability involved an oversight with TikTok’s deep-linking function.


The vulnerability allowed hackers to bypass the app’s deep-link verification function. Attackers could force the app to load an arbitrary URL to the app’s WebView, allowing the URL to then access the WebView’s attached JavaScript bridges and grant functionality to attackers.


Most marketers know, but for those who don’t, a deeplink is a hyperlink that links to a specific component in a mobile app and consists of a scheme and, usually, a host, Microsoft explains. When a deeplink is clicked, the Android package manager queries all the installed applications to see which one can handle the deeplink and then routes it to the handler of that link. (More explained here.)


“Performing a vulnerability assessment of TikTok, we determined that the issues were affecting both flavors of the app for Android, which have over 1.5 billion installations combined via the Google Play Store,” Microsoft said. 


Microsoft’s team informed TikTok in February. TikTok quickly responded by releasing a fix to address the reported vulnerability.


Microsoft’s security team found a vulnerability in the TikTok Android app — a one-click exploit that could have allowed hackers to hijack millions of accounts, the 365 Defender Research Team on Wednesday explained in a post.

 

MediaPost.com: Search & Performance Marketing Daily

(29)

Post navigation

← What will have the biggest impact on consumer holiday shopping? The Metaverse Hits An Impasse →

You may also Like

Search Engine Optimization

How to Generate More Web Content from Google Hangouts on Air

Freelancing

How To Go Freelance Without Going Broke

Business Effectiveness

Is Your Job Making You Gain Weight?

Customer Relationship Managemnet

4 simple ways small businesses can use data to build better customer relationships

Corporate Appointments

X’s former head of global affairs takes job with Musk rival Sam Altman

Customer Journey

3 strategies to create better customer journeys across any channel

Website Landing Pages

5 Landing Page Mistakes Hurting Your Results

Google Advertisement

So we have 45 more characters in AdWords text ads… Now what?

Shopping Campaigns

How to make a holiday shopping campaign for low budget accounts

Employee Advocacy

The Right Way to Terminate an Employee

SEM & SEO

SEMrush

Recent Posts

  • 10 ways teachers can use AI
  • OpenAI is reportedly pushing back the launch of its ‘adult mode’ even further
  • 7 leadership moves that matter before you step in front of your team
  • Your role was eliminated. Your capability wasn’t
  • Daylight saving time starts Sunday. Here’s 11 things you can do to adjust to losing an hour of sleep

Pages

  • About Us
  • Advertisement and Content Publishing
  • Contact Us to Publish
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions

Proudly powered by WordPress | Child Theme by: Crayonux

Report Post

« »

 

Your Name:

Your Email:

Please tell us why do you think this post is inappropriate and shouldn't be there:


Cancel Report