Skip to main content

This severe TikTok vulnerability gives hackers 70 ways to steal your info

After internal testing, Microsoft discovered an exploit in the Android version of TikTok that could have given attackers access to huge amounts of personal data with a single click.

The vulnerability has already been fixed, and it does not appear that anyone has been affected by the exploit. The attackers could have used this vulnerability to access user profiles, allowing outside forces to publicize private videos, send messages, and even upload videos.

Recommended Videos

The exploit took advantage of the way TikTok handles WebView code by bypassing deep link verification. When a TikTok user selects an affected deep link, the URL could access JavaScript bridges that granted attackers functionality on the account. JavaScript bridges continue to pose a security risk on a variety of apps, and Microsoft, in a blog post, emphasized how “… collaboration within the security community is necessary to improve defenses for the overall digital ecosystem.”

Please enable Javascript to view this content

The exploit could have affected over 1.5 billion TikTok installations from the Google Play Store.

The vulnerability is actually a combination of several issues that, when combined together, could give attackers access to these accounts. Microsoft details all of its findings and how it discovered the exploit in its in-depth blog post.

When Microsoft notified TikTok’s security team of the issue, they “responded by releasing a fix to address the reported vulnerability, now identified as CVE-2022-28799, and users can refer to the CVE entry for more information. We commend the efficient and professional resolution from TikTok’s security team.”

News of this exploit comes on the heels of frequent reports of TikTok’s excessive data collection. Hopefully, this quick patch reflects how seriously the company takes user data and privacy. Microsoft and TikTok both recommend you double-check to make sure you are on the latest version of the app to avoid any issues.

Caleb Clark
Former Digital Trends Contributor
Caleb Clark is a full-time writer that primarily covers consumer tech and gaming. He also writes frequently on Medium about…
Google’s Gemini makes adding events to Calendar easier than ever
Gemini and Gmail apps on the home screen of an Android phone.

In a Workspace Updates blog post, Google announced a new button that adds events to Google Calendar directly from Gmail based on email details. The new button will only be added if Gemini thinks the email describes an event.

When you click the button, a sidebar opens, letting you know that Gemini has added the event. However, it also tells you it couldn't invite attendees yet. It tells you to invite them yourself by modifying the events in Google Calendar. Additionally, Gmail shows you a "Show me what's on my calendar that day" button so you know what else is on your to-do list. When you view the event in Calendar, it says an external source created it.

Read more
Windows 11 to simplify battery monitoring with mobile-inspired icons
Windows 11 logo on a laptop.

Microsoft is preparing changes to its laptop battery charge indicators, which should be coming to future versions of Windows 11 in the coming months. 

The updates are set to make clear distinctions between the different battery states, such as an unplugged battery, a charging battery, or a battery with an unknown status. While all Windows 11 users are scheduled to get the new battery-level icons, Windows 11 Insiders are set to get first dibs. According to Windows Latest, Microsoft previewed the battery icons to pre-release users in a video conference in early March. This conference revealed the icon images but did not give much further information about the coming design changes, such as a release timeline. 

Read more
Chromebooks to get Pixel battery health feature in ChromeOS update
The back of the Asus Chromebook CX1.

Chromebooks will soon get a battery-preserving feature that has already proved popular on Google Pixel smartphones that run the latest Android 15 software. 

The feature will limit device charging to 80%. This update will help Chromebook batteries last longer overall. The feature is set to be a part of the ChromeOS 134 update, which is scheduled for next month. 
New ChromeOS policy for battery longevity

Read more