Moneycontrol PRO
HomeNewsTechnologyMicrosoft flags TikTok flaw that could compromise user accounts

Microsoft flags TikTok flaw that could compromise user accounts

The bug, since fixed, was in the Android version of the TikTok app and would have allowed hackers to hijack an account

September 02, 2022 / 13:46 IST
(Representational Image: Solen Feyissa via Unsplash)

Microsoft has disclosed a vulnerability in TikTok that could give hackers access to user accounts, putting their private videos at risk.

The Redmond-based technology giant's 365 Defender Research Team has been credited with the find and the flaw has since been plugged by TikTok.

Microsoft said the bug in the Android app would have allowed bad actors to take over accounts with a single click. It worked by having the user click on a malicious link, which would have then allowed the bad actors to hijack the account.

TikTok has two different versions of the Android app, one for East and Southeast Asia and another for the rest of the world. Microsoft said the bug was present on both versions of the app.

"Performing a vulnerability assessment of TikTok, we determined that the issues were affecting both flavors of the app for Android, which have over 1.5 billion installations combined via the Google Play Store," Microsoft said in a blog post.

"Attackers could have leveraged the vulnerability to hijack an account without users’ awareness if a targeted user simply clicked a specially crafted link. Attackers could have then accessed and modified users’ TikTok profiles and sensitive information, such as by publicizing private videos, sending messages, and uploading videos on behalf of users," wrote the technology giant.

The vulnerability was disclosed to TikTok in February of this year and the company quickly issued a patch to fix the issue.

Microsoft also emphasised the importance "of exercising caution when clicking unknown links" as they could be potential gateways to malicious actors.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Sep 2, 2022 01:46 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347