Microsoft discovered (and reported) a very serious vulnerability in the Android version of the TikTok app in February. This vulnerability allowed attackers to take control of TikTok accounts “quickly and silently” by getting targets to click on a specially crafted malicious link.

“knowledge users’, if a targeted user simply clicked on a specially crafted link,” said Dimitrios Valsamaras of the Microsoft 365 Defender Research Team.
See also: TikTok's in-app browser tracks your every move
“The attackers could then access and modify users , posting private videos, sending messages, and uploading videos on behalf of the users.“.
Clicking on the link revealed more than 70 JavaScript methods that could be used by an attacker with the help of an exploit designed to compromise the TikTok app's WebView (an Android system component used by the vulnerable app to display web content).
Using the exposed methods, attackers could access or modify users or perform authenticated HTTP requests.
In short, by successfully exploiting this vulnerability someone could:
- retrieve users' authentication tokens
- retrieve or modify TikTok users' account data, including private videos and profile settings
“A vulnerability was found in the WebView in the TikTok Android app via an unvalidated deeplink to an un-sanitized parameter. This could have resulted in account compromise via a JavaScript interface,” the HackerOne report further explains.
See also: Chrome extensions with 1.4 million downloads steal browsing data

The vulnerability in the Android version of TikTok apps has now been fixed
The vulnerability, which is tracked as CVE-2022-28799, has now been patched with the release of TikTok version 23.7.3, released less than a month after Microsoft.
Microsoft says it has not yet found any exploits for CVE-2022-28799.
TikTok users can protect themselves from similar security issues by avoiding opening links that come from untrusted sources, promptly applying all released updates, only installing apps from official sources, and reporting any strange app behavior as soon as possible.
See also: Apple: Fixes zero-day bug affecting older iPhones
More information about the vulnerability and how it could have been used in attacks can be found in Microsoft's report.
This isn't the first time TikTok has patched a vulnerability that could have allowed accounts to be compromised. It fixed a few such bugs in November 2020. Additionally, the company has addressed security that allowed users' personal information to be stolen.
It is important to patch vulnerabilities found in apps like TikTok immediately . The Chinese app is extremely popular with over 1 billion installs on Android devices. This means a huge number of users could be affected by the security issues.
Source: www.bleepingcomputer.com
