Skip to main content
  1. Home
  2. Social Media
  3. News

TikTok vulnerability could have allowed hackers to take over users’ profiles

Add as a preferred source on Google

Israel-based security research firm Check Point says it found multiple severe loopholes within short-form video app, TikTok that could have potentially allowed hackers to take over users’ accounts, access their private data, and upload videos on their behalf. The vulnerability made it possible for intruders to masquerade as TikTok and send official text messages with malicious links.

The vulnerabilities have been patched since November when Check Point discovered them and warned TikTok through server-side changes as well as app updates. Therefore, if you haven’t updated TikTok in a while, head over to the app store and do so immediately.

Recommended Videos

“TikTok is committed to protecting user data. Like many organizations, we encourage responsible security researchers to privately disclose zero-day vulnerabilities to us. Before public disclosure, Check Point agreed that all reported issues were patched in the latest version of our app. We hope that this successful resolution will encourage future collaboration with security researchers,” said Luke Deshotels, a member of TikTok’s team of security researchers, in a statement.

The bug originated from the download link request feature on TikTok’s website. But due to a programming oversight, hackers could tap into the company’s official SMS channel, and instead of the download link, forward users a malicious one. When someone clicked on it, they would unknowingly end up ceding access to a range of sensitive sections of their TikTok account. Once in, the hacker could upload videos, make private posts public, delete files, view personal information such as email addresses, and more.

That’s not all. Check Point was able to unearth another security loophole which could have let hackers gain access to TikTok’s database of millions of users by inserting a piece of malicious code inside the official website. The firm’s researchers, through this, managed to retrieve accounts’ private data including their names and birth dates.

TikTok claims it hasn’t found any affected users or instances of abuse yet.

In a little over two years, TikTok has rapidly accumulated over a billion users and downloads across the globe. However, the social network has come under lawmakers’ crosshairs in the United States primarily due to its Chinese roots. Privacy vulnerabilities such as this one could end up compounding those concerns further.

To combat the increased scrutiny, TikTok’s parent company, ByteDance has mulled setting up a headquarters outside of China. A recent Bloomberg report also said that ByteDance may be considering letting go of TikTok altogether or sell a majority stake to put an end to the growing concerns.

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
Facebook now has an answering genie for all your burning questions, just like Google Search
Meta's new AI Mode answers your questions using real posts from Facebook Groups and Reels instead of generic search results.
Screenshots showing Facebook's new AI-powered Search results

Facebook has rolled out a batch of AI-powered features, with the headliner being AI Mode, a new way to get answers to questions directly inside the app using Meta AI.

An AI layer on top of Facebook Search

Read more
Yet another study finds too many kids are seeing harmful content on social media
Despite the UK's Online Safety Act coming into force last year, a new study found that harmful content is still reaching a third of teenagers and nearly half of all girls on social media every week.
a boy using iPhone

A year after the UK's Online Safety Act came into force, a new study has found that harmful social media content is still reaching teenagers at nearly the same rate as before the law took effect. Research by the Molly Rose Foundation (via The Guardian) found that a third of all UK teenagers and nearly half of all girls encountered suicide, self-harm, depression, or eating disorder content on social media in the span of just one week.

What the data shows

Read more
Facebook and Messenger outage sparks logout panic as Meta services stumble
Downdetector reports spiked as users said Facebook and Messenger kicked them out, with Instagram also affected.
Meta featured image

Facebook and Messenger users were briefly knocked offline Friday morning, with many saying they had been logged out and couldn’t get back in. The Facebook and Messenger outage sent users to X, Reddit, and other platforms to check whether the problem was widespread or tied to their own accounts.

Downdetector showed the first visible surge in Facebook complaints around 9:52 a.m. ET.

Read more