Hack Any TikTok Account by SMS
Researchers Demonstrate How to Hack Any TikTok Account by Sending SMS
Researchers have found that the app contained potentially dangerous vulnerabilities that could have allowed remote attackers to hijack any user account just by knowing the mobile number of targeted victims.
Cyber-security researchers at Check Point revealed that chaining multiple vulnerabilities allowed them to remotely execute malicious code and perform unwanted actions on behalf of the victims without their consent.
The reported vulnerabilities include low severity issues like SMS link spoofing, open redirection, and cross-site scripting (XSS) that when combined could allow a remote attacker to perform high impact attacks, including:
- delete any videos from victims' TikTok profile,
- upload unauthorized videos to victims' TikTok profile,
- make private "hidden" videos public,
- reveal personal information saved on the account, such as private addresses and emails.
Watch a Demonstrated video here:
Comments
Post a Comment