TikTok faced two vulnerabilities that could allow attackers to take over accounts with a single click when linking with users who have signed up via third-party applications.
The social media platform owned by ByteDance, based in Beijing, is used for sharing short looping videos (3 to 60 seconds).
TikTok's Android app currently has over 1 billion installs according to official Google Play Store , and in April 2020 it surpassed 2 billion installs based on Sensor Tower Store Intelligence estimates.

German bug hunter Muhammed Taskiran discovered a cross-site scripting (XSS) security flaw in a TikTok URL parameter that reflects its value without proper sanitization (data sanitization is the process of ensuring that data conforms to the requirements of the subsystem to which it is passed).
Taskiran found reflected XSS that could also lead to data exfiltration, while fuzz – fuzz testing is an automated software testing – tested the company's domains www.tiktok.com and m.tiktok.com.
It also found a TikTok API endpoint vulnerable to cross-site request forgery (CSRF) attacks that allowed account passwords to be changed for users who registered using third-party apps.
“My endpoint allowed me to set a new password on user accounts that had used third‑party applications to register”, said Taskiran.
"I combined both vulnerabilities by creating a simple JavaScript payload – enabling CSRF – which I have inserted into the vulnerable URL beforehand, to create a 'one-click account withdrawal'."
Taskiran reported the vulnerabilities in TikTok on August 26, 2020, with the company fixing the issues and rewarding the bug bounty hunter with the amount of $3,860 on September 18.
TikTok also faced a security vulnerability in its infrastructure, allowing potential attackers to break into accounts to manipulate users' videos and steal information .
The security issues were disclosed to ByteDance by Check Point researchers in late November 2019, with the company fixing the bugs within a month.
Attackers could have used TikTok's SMS system to exploit vulnerabilities to upload unauthorized videos, delete or move users' videos from private to public, and steal sensitive personal data.
“TikTok is committed to protecting user data,” TikTok security engineer Luke Deshotels said at the time. “Like many organizations, we encourage security researchers to privately disclose to us any zero-day vulnerabilities they may discover.”
