• We just launched and are currently in beta. Join us as we build and grow the community.

Researchers demonstrate how to hack any TikTok account by sending SMS

aisodjioj

Data Serialization Pro
A Rep
0
0
0
Rep
0
A Vouches
0
0
0
Vouches
0
Posts
190
Likes
158
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 200 XP
TikTok, the 3rd most downloaded app in 2019, is under intense scrutiny over users' privacy, censoring politically controversial content and on national-security grounds—but it's not over yet, as the security of billions of TikTok users would be now under question.
The famous Chinese viral video-sharing app contained potentially dangerous vulnerabilities that could have allowed remote attackers to hijack any user account just by knowing the mobile number of targeted victims.
In a report privately shared with The Hacker News, cybersecurity researchers at Check Point revealed that chaining multiple vulnerabilities allowed them to remotely execute malicious code and perform unwanted actions on behalf of the victims without their consent.
The reported vulnerabilities include low severity issues like SMS link spoofing, open redirection, and cross-site scripting (XSS) that when combined could allow a remote attacker to perform high impact attacks, including:
  • delete any videos from victims' TikTok profile,
  • upload unauthorized videos to victims' TikTok profile,
  • make private "hidden" videos public,
  • reveal personal information saved on the account, such as private addresses and emails.
The attack leverages an insecure SMS system that TikTok offers on its website to let users send a message to their phone number with a link to download the video-sharing application.
Video:
According to the researchers, an attacker can send an SMS message to any phone number on behalf of TikTok with a modified download URL to a malicious page designed to execute code on a targeted device with already installed TikTok app.
 

452,292

323,341

323,350

Top