Posted on September 2nd, 2022.
Security researchers have discovered a high severity vulnerability in TikTok’s Android app which could allow attackers to remotely hijack user accounts.
Microsoft reported CVE-2022-28799 to the social media giant in February 2022, after which TikTok promptly fixed the issue. Although the app has an estimated 1.5 billion downloads on the Play Store, the bug has not yet been exploited in the wild, Microsoft claimed.
“The vulnerability allowed the app’s deeplink verification to be bypassed,” explained Microsoft. “Attackers could force the app to load an arbitrary URL to the app’s WebView, allowing the URL to then access the WebView’s attached JavaScript bridges and grant functionality to attackers.”
In fact, Microsoft identified over 70 exposed JavaScript methods which, when paired with an exploit to hijack WebView such as the discovered bug, could be used to grant functionality to the attackers.
By doing so, attackers can:
“The attacker’s server returns an HTML page containing JavaScript code to send video upload tokens back to the attacker as well as change the user’s profile biography.”
With full control over users’ accounts, attackers could change their profile details, send messages, upload videos and even publish private videos.