Skip to main content

This severe TikTok vulnerability gives hackers 70 ways to steal your info

After internal testing, Microsoft discovered an exploit in the Android version of TikTok that could have given attackers access to huge amounts of personal data with a single click.

The vulnerability has already been fixed, and it does not appear that anyone has been affected by the exploit. The attackers could have used this vulnerability to access user profiles, allowing outside forces to publicize private videos, send messages, and even upload videos.

Recommended Videos

The exploit took advantage of the way TikTok handles WebView code by bypassing deep link verification. When a TikTok user selects an affected deep link, the URL could access JavaScript bridges that granted attackers functionality on the account. JavaScript bridges continue to pose a security risk on a variety of apps, and Microsoft, in a blog post, emphasized how “… collaboration within the security community is necessary to improve defenses for the overall digital ecosystem.”

Please enable Javascript to view this content

The exploit could have affected over 1.5 billion TikTok installations from the Google Play Store.

The vulnerability is actually a combination of several issues that, when combined together, could give attackers access to these accounts. Microsoft details all of its findings and how it discovered the exploit in its in-depth blog post.

When Microsoft notified TikTok’s security team of the issue, they “responded by releasing a fix to address the reported vulnerability, now identified as CVE-2022-28799, and users can refer to the CVE entry for more information. We commend the efficient and professional resolution from TikTok’s security team.”

News of this exploit comes on the heels of frequent reports of TikTok’s excessive data collection. Hopefully, this quick patch reflects how seriously the company takes user data and privacy. Microsoft and TikTok both recommend you double-check to make sure you are on the latest version of the app to avoid any issues.

Caleb Clark
Former Digital Trends Contributor
Caleb Clark is a full-time writer that primarily covers consumer tech and gaming. He also writes frequently on Medium about…
If you’re considering a Sky Blue MacBook Air, you might want to act quickly
M4 MacBook Air

Apple has announced two iPad models, the Mac Studio, and the MacBook Air so far this year, and out of all of these products, the Sky Blue MacBook Air is expected to sell the most. Bloomberg's Mark Gurman says Apple is expecting high demand for all the latest devices but the new color option for the budget MacBook is expected to be particularly hot.

https://x.com/markgurman/status/1898825550028013879

Read more
Apple Vision Pro tipped for a serious upgrade at WWDC 2025
Alan Truly enjoys the Apple Vision Pro's look and pinch user interface.

News about the Vision Pro or its future successors has been pretty slow lately but according to Bloomberg's Mark Gurman, Apple is planning a big release for visionOS 3.

There aren't many details at the moment, but Gurman says that Apple "can't just let the Vision Pro die out" because it has invested too much into the technology and it needs to keep the device alive and updated for the people who bought it. He says visionOS 3 will be "a pretty feature-packed release," and that we'll find out more about it at WWDC this year.

Read more
My Mac Pro hopes have been dashed, and Apple can’t save it this year
A person uses an Apple Mac Pro alongside three monitors and an editing console in a darkened room.

Last week, Apple revealed a new Mac Studio equipped with M4 Max and M3 Ultra chips. No, that’s not a typo -- the company really did launch a new Mac with chips from two different generations, where the less powerful chip is from the newer iteration. As I’ve written before, it’s a confusing, ridiculous situation, and one that must be driving Apple’s marketing division mad.

But at first, it seemed like there was a glimmer of reasoning behind the decision: Apple could save the rumored M4 Ultra chip for the Mac Pro and bring back some proper differentiation to the Mac lineup. Instead of having the Mac Studio and the Mac Pro offer the same maximum performance (as we have now), the Mac Pro would finally get a sizeable boost to tempt power-hungry pro users.

Read more