Security News > 2020 > August > TikTok Surreptitiously Collected Android User Data Using Google-Prohibited Tactic

TikTok Surreptitiously Collected Android User Data Using Google-Prohibited Tactic
2020-08-12 12:16

TikTok has been collecting unique identifiers from millions of Android devices without their users' knowledge using a tactic previously prohibited by Google because it violated people's privacy, new research has found.

The app bundled the MAC address with other device data and sent it to ByteDance upon the app's first installation and opening on a new device, according to the report.

Mobile apps collect various data on users for advertising purposes, which has always been a point of contention for privacy advocates.

President Trump recently threatened to ban the app in the United States out of fear that it's surreptitiously collecting data on U.S. government employees and contractors to use in China's cyber activities against the United States.

TikTok has said it doesn't share data with the Chinese government and would not violate user privacy even if asked, according to the WSJ. However, many security experts have warned that due to the security flaws of the app and China's stance on cybersecurity, it's likely the Chinese government has access to whatever data the app does.


News URL

https://threatpost.com/tiktok-surreptitiously-collected-android-user-data-using-google-prohibited-tactic/158289/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Android 4 0 17 2 0 19