As confirmed by security analysts, the TikTok video platform suffered a serious vulnerability that gave access to a good amount of private user data. Unique IDs, user names, avatars and even the phone number, the information was accessible after a very specific access process. The error is now fixed.
TikTok is one of the social networks that has experienced the greatest growth in recent times: it is expected that by the end of 2021 the platform reach 1.2 billion unique users. This significant volume of use has another drawback: the attention of those who seek access to private data. We recently learned that TikTok offered a gateway to some of that data.
The vulnerability detected in the platform was corrected, so there would no longer be a risk that attackers could use it. There is no evidence that it will be used massively to obtain user data, at least This is what Check Point ensures, firm that made the discovery.
Check Point used the user registration service to take advantage of the cookies used by TikTok in authentication through HTTP message. Check Point was able to automate the process, managing to scale the upload and synchronization of contacts; until obtaining user data that is associated with said contacts, such as name, ID, avatar and phone number. Of course, the phone number is only associated with the account if the user decides to share this data with TikTok (it is essential to search for other contacts on the social network).
{“file”: “https://webediaespana.video.content-hub.app/default/video/73/f3/62/5e9dc68e4bd22f1a3d/default-progressive-adaptive.m3u8”, “image”: “https: // webediaespana.delivery.content-hub.app/image/61/a7/72/5e9dc6db4bd22f1ae9/original/mini-tik-tok.jpeg “}
TikTok has already fixed the vulnerability. However, it is best not to share data as private as the phone number with the platform.
Via | Cnet
More information | Check Point
–
The news
A TikTok vulnerability gave access to users’ private data, including phone number
was originally published in
Xataka Android
by
Ivan Linares
.
Exploring the Top 5 Voice AI Alternatives: What Sets Them Apart?
The Rise of Spatial Computing: Evolution of Human-Computer Interaction
Data Loss on Windows? Here's How Windows Recovery Software Can Help
Integrating Widgets Seamlessly: Tips for Smooth Implementation and Functionality
School sports days are a fun event for all students, but it’s important that the…