TikTok patches security flaw that could leave your activity open to anyone

TikTok on a phone in front of the USA flag
(Image credit: CFOTO/Future Publishing via Getty Images)

UPDATE - In response to our initial story, a TikTok spokesperson told TechRadar Pro, "Through our partnership with the security researchers at Imperva, we discovered and quickly fixed a vulnerability present in some older versions of the web app. We thank the Imperva researchers for their efforts to help identify potential issues so we can swiftly resolve them."

Cybersecurity researchers from Imperva have uncovered a flaw in the popular social media app TikTok which could have allowed threat actors to exfiltrate sensitive data from victim devices to be used in identity theft attacks, phishing, or for blackmail.

The vulnerability, which has since been fixed, was found in the way the app handled incoming messages. Explaining the method, the researchers said the attackers could send a malicious message to the TikTok web application through the PostMessage API, which would glide past any security measures. 

The message event handler would then process the message and deem it secure, granting the attacker access to the valuable information.

User account details

By exploiting the vulnerability, the attackers could gain access to a treasure trove of valuable data, such as user device data (device type, operating system, browser used, etc.), videos viewed (what videos the victim viewed), the time spent on each video, user account data (usernames, videos, other account details), search queries (what the user searched for on the platform).

Even without the vulnerabilities, TikTok is a controversial app, to put it mildly. It was built by a Chinese company called ByteDance, and has more than 1.5 billion users (more than 150 million in the U.S. alone). 

Recently, the US government started scrutinizing and banning Chinese companies, claiming their government has a tight grip on them and could force them to allow for unauthorized backdoor access at any point.

Huawei was banned from developing the 5G infrastructure in the States, for that very reason. As for TikTok, the U.S. government first forced the company to store all of the data in the country, and then recently told its employees to remove the app from government-issued devices, citing matters of national security. 

TikTok, much like many other Chinese companies, is denying any involvement in any wrongdoing. 

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
The TikTok logo appears on a smartphone screen with the United States flag in the background
Forget the US TikTok ban – what we need is better social media and privacy laws
DeepSeek
DeepSeek accused of sharing users' data with TikTok's ByteDance in another blow around privacy concerns
Abstract image of cyber security in action.
TikTok’s American ownership rule ignores bigger IoT threat
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Participants hold up signs in support of TikTok at a news conference outside the U.S. Capitol Building on March 12, 2024 in Washington, DC.
US TikTok ban: the clock is ticking for Americans' digital freedoms
China flag and EU flag on cloudy sky. Waving in the sky
TikTok among six tech firms under fire for sending Europeans' personal data to China
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)