Security News > 2020 > January > Researchers Demonstrate How to Hack Any TikTok Account by Sending SMS

Researchers Demonstrate How to Hack Any TikTok Account by Sending SMS
2020-01-08 02:02

TikTok, the 3rd most downloaded app in 2019, is under intense scrutiny over users' privacy, censoring politically controversial content and on national-security grounds-but it's not over yet, as the security of billions of TikTok users would be now under question.

The famous Chinese viral video-sharing app contained potentially dangerous vulnerabilities that could have allowed remote attackers to hijack any user account just by knowing the mobile number of targeted victims.

The reported vulnerabilities include low severity issues like SMS link spoofing, open redirection, and cross-site scripting that when combined could allow a remote attacker to perform high impact attacks, including:delete any videos from victims' TikTok profile,.

The attack leverages an insecure SMS system that TikTok offers on its website to let users send a message to their phone number with a link to download the video-sharing application.

"Redirecting the user to a malicious website will execute JavaScript code and make requests to Tiktok with the victims' cookies."


News URL

http://feedproxy.google.com/~r/TheHackersNews/~3/oFxt48B8hO8/hack-tiktok-account.html