{"id":202664,"date":"2022-09-02T11:49:12","date_gmt":"2022-09-02T09:49:12","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=202664"},"modified":"2025-07-01T20:28:52","modified_gmt":"2025-07-02T03:28:52","slug":"vulnerability-tiktok-android-app","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/vulnerability-tiktok-android-app\/","title":{"rendered":"Vulnerability in TikTok&#8217;s Android app was allowing attackers to secretly access user accounts"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">TikTok is a hot topic these days with politicians all over the Western World frothing at the mouth at the possibility of the Chinese app getting its hands on their citizens\u2019 data. There are other security concerns that need to be taken seriously, however, such as the more traditional cybersecurity issues we regularly report on here at Softonic. Today we have <strong>news of a vulnerability in the TikTok app for Android<\/strong> that has been allowing attackers to secretly access users\u2019 data. Let\u2019s go through the details now:<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"TikTok\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-xl,f_auto\/p\/25d01a14-3485-42e7-a253-e5050ac51dd1\/3735921813\/tik-tok-icon.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">TikTok<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/tik-tok.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download Now<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/tik-tok.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">It is a popular method for cybersecurity and antivirus specialists to raise the profile of their products by reporting on security vulnerabilities they have uncovered. This is even the same for security researchers at software giants like Microsoft. The Microsoft Defender 365 Research Team has <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/08\/31\/vulnerability-in-tiktok-android-app-could-lead-to-one-click-account-hijacking\/\">release<\/a><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/08\/31\/vulnerability-in-tiktok-android-app-could-lead-to-one-click-account-hijacking\/\" target=\"_blank\" rel=\"noreferrer noopener\">d<\/a><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/08\/31\/vulnerability-in-tiktok-android-app-could-lead-to-one-click-account-hijacking\/\"> a report<\/a> exposing <strong>a security vulnerability in the TikTok Android app that \u201ccould lead to one-click account hijacking\u201d<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Fortunately, although the vulnerability was active for a period of time, it was <strong>quite complex and required a chain of multiple issues to occur at once<\/strong>, in order for the exploit to be taken advantage of. This means that the vulnerability has now been closed before any seeming exploits have been actioned.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is great news because although it would have been difficult to exploit, <strong>the vulnerability was quite serious<\/strong>, with the Defender 365 team reporting:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>\u201cThe vulnerability allowed the app\u2019s deeplink verification to be bypassed. Attackers could force the app to load an arbitrary URL to the app\u2019s WebView, allowing the URL to then access the WebView\u2019s attached JavaScript bridges and grant functionality to attackers.\u201d<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once again, a security issue is <strong>highlighting the need for vigilance<\/strong> when you are online. It is more important than ever to take care whenever you are clicking links or downloading files. As always in these cases, we recommend you refer to our <a href=\"https:\/\/en.softonic.com\/articles\/how-to-detect-fakescam-emails-and-avoid-phishing-attacks-hi-res-version\" target=\"_blank\" rel=\"noreferrer noopener\">phishing scam and fake link infographic<\/a> every time you come across something suspicious.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Image via: <a href=\"https:\/\/www.flickr.com\/photos\/26344495@N05\/51204244035\" target=\"_blank\" rel=\"noreferrer noopener\">Flickr<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>TikTok is a hot topic these days with politicians all over the Western World frothing at the mouth at the possibility of the Chinese app getting its hands on their citizens\u2019 data. There are other security concerns that need to be taken seriously, however, such as the more traditional cybersecurity issues we regularly report on &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/vulnerability-tiktok-android-app\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Vulnerability in TikTok&#8217;s Android app was allowing attackers to secretly access user accounts&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9073,"featured_media":202670,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[2336],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-202664","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectiontik-tok"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/202664","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=202664"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/202664\/revisions"}],"predecessor-version":[{"id":323264,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/202664\/revisions\/323264"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/202670"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=202664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=202664"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=202664"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=202664"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=202664"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=202664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}