RICK REA: Helping You Grow Through Online Marketing
  • Home
  • Blog
    • Social Media News
    • SEO Marketing News
    • Digital Trends News
    • Photography News
    • Mobile Marketing
    • Business News
    • Gadget News
    • Printing News
  • Contact
  • About
  • Subscribe

Mobile Marketing



Microsoft Identifies TikTok Vulnerability Allowing One-Click Account Hijacking

8/31/2022

0 Comments

 
https://ift.tt/dnG2HrC

Microsoft Identifies TikTok Vulnerability Allowing One-Click Account Hijacking

https://ift.tt/YxhrS19

Microsoft’s security team has found a vulnerability in the TikTok Android app.

The 365 Defender Research Team on Wednesday explained in a post how the one-click exploit could have allowed hackers to hijack millions of accounts.

“The vulnerability, which would have required several issues to be chained together to exploit, has been fixed and we did not locate any evidence of in-the-wild exploitation,” the company wrote in a blog post. “Attackers could have leveraged the vulnerability to hijack an account without users’ awareness if a targeted user simply clicked a specially crafted link.”

Attackers could have accessed and modified users’ TikTok profiles and sensitive information, such as by publicizing private videos, sending messages, and uploading videos on behalf of users, the company said.

Microsoft’s security team explains in the post that the vulnerability involved an oversight with TikTok’s deep-linking function.

advertisement

advertisement

The vulnerability allowed hackers to bypass the app’s deep-link verification function. Attackers could force the app to load an arbitrary URL to the app’s WebView, allowing the URL to then access the WebView’s attached JavaScript bridges and grant functionality to attackers.

Most marketers know, but for those who don’t, a deeplink is a hyperlink that links to a specific component in a mobile app and consists of a scheme and, usually, a host, Microsoft explains. When a deeplink is clicked, the Android package manager queries all the installed applications to see which one can handle the deeplink and then routes it to the handler of that link. (More explained here.)

“Performing a vulnerability assessment of TikTok, we determined that the issues were affecting both flavors of the app for Android, which have over 1.5 billion installations combined via the Google Play Store,” Microsoft said. 

Microsoft’s team informed TikTok in February. TikTok quickly responded by releasing a fix to address the reported vulnerability.





Mobile Marketing

via MediaPost.com: mobile https://ift.tt/dc9OCuq

August 31, 2022 at 03:14PM


0 Comments



Leave a Reply.

    Categories

    All

    Archives

    April 2025
    March 2025
    February 2025
    January 2025
    December 2024
    November 2024
    October 2024
    September 2024
    August 2024
    July 2024
    June 2024
    May 2024
    April 2024
    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    September 2019
    August 2019
    July 2019
    June 2019
    May 2019
    April 2019
    March 2019
    February 2019
    January 2019
    December 2018
    November 2018
    October 2018
    September 2018
    August 2018
    July 2018
    June 2018
    May 2018
    April 2018
    March 2018
    February 2018
    January 2018
    December 2017
    November 2017
    October 2017
    September 2017
    August 2017
    July 2017
    June 2017
    May 2017
    April 2017
    March 2017
    February 2017

    RSS Feed

Powered by Create your own unique website with customizable templates.
  • Home
  • Blog
    • Social Media News
    • SEO Marketing News
    • Digital Trends News
    • Photography News
    • Mobile Marketing
    • Business News
    • Gadget News
    • Printing News
  • Contact
  • About
  • Subscribe