TikTok, the famous Chinese viral video-sharing app had potentially dangerous vulnerabilities that could have let remote attackers to hijack any user account by just knowing the mobile number of targeted victims.
TikTok which is the 3rd most downloaded app in 2019 was under intense scrutiny over users’ privacy, censoring politically controversial content and on national-security grounds. But now the security of its billions of users was at risk.
The cybersecurity researchers at Check Point revealed that chaining multiple vulnerabilities allowed them to remotely execute malicious code and perform unwanted actions on behalf of the victims without their knowledge.
The vulnerabilities include low severity issues like SMS link spoofing, open redirection, and cross-site scripting (XSS) which when combined would let a remote attacker to perform high impact attacks like
- deleting any videos from victims’ TikTok profile,
- uploading unauthorized videos to victims’ TikTok profile,
- making private “hidden” videos public,
- reveal personal information saved on the account, like private addresses and emails.
The attack leverages an insecure SMS system that TikTok offers on its website to let users send a message to their phone number with a link to download the video-sharing application
The researchers stated that an attacker could send an SMS message to any phone number on behalf of TikTok with a modified download URL to a malicious page designed to execute code on a targeted device with already installed TikTok app.
This technique is commonly known as cross-site request forgery attack, wherein attackers trick authenticated users into executing an unwanted action.
Check Point reported these vulnerabilities to the developer of TikTok, ByteDance in late November 2019, who then released a patched version of its mobile app within a month to protect its users from hackers.
Those users who are not running the latest version of TikTok available on official app stores for Android and iOS, are highly recommended to update it at the earliest.