The company behind the popular video- sharing app TikTok announced last week that it had launched a public bug bounty program , in partnership with the HackerOne platform , to detect potential vulnerabilities.

With this move, the TikTok developer is inviting white hat hackers to find vulnerabilities in its main sites , as well as in many subdomains and in its Android and iOS applications.
According to TikTok, bug bounty participants can earn between $1,700 and $6,900 for a serious vulnerability, while for the detection of a critical bug, the company is willing to give up to $14,800. The severity of the vulnerability is determined based on the CVSS score.
Security researchers have previously identified significant security in the TikTok app, and the company claims to have paid out more than $40,000 through a bug bounty program so far.
Previously, TikTok had a vulnerability disclosure policy, but it only rewarded certain reports and did not have a clear payment structure for researchers.
“This collaboration will help us gain insights from the world’s leading security researchers, academic scholars, and independent experts to better uncover potential threats and make our defenses even stronger,” said Luna Wu of TikTok’s Global Security Team.

The US government has long been trying to ban TikTok in the United States, deeming the app a national security. The company behind TikTok challenged the decision in court, and the judge sided with the Chinese company, temporarily blocking the ban.
According to SecurityWeek, Washington said it would allow TikTok to be used in the country if its parent company, Bytedance, agreed to sell its operations to a U.S.. Initially, there was an attempt to strike a deal with Microsoft, but the partnership did not move forward.
