Microsoft Finds Account Takeover Bug in TikTok
Security researchers have discovered a high severity vulnerability in TikTok’s Android app which could allow attackers to remotely hijack user accounts.
Microsoft reported CVE-2022-28799 to the social media giant in February 2022, after which TikTok promptly fixed the issue. Although the app has an estimated 1.5 billion downloads on the Play Store, the bug has not yet been exploited in the wild, Microsoft claimed.
“The vulnerability allowed the app’s deeplink verification to be bypassed,” explained Microsoft. “Attackers could force the app to load an arbitrary URL to the app’s WebView, allowing the URL to then access the WebView’s attached JavaScript bridges and grant functionality to attackers.”
In fact, Microsoft identified over 70 exposed JavaScript methods which, when paired with an exploit to hijack WebView such as the discovered bug, could be used to grant functionality to the attackers. Read More...