Detailing their findings in a blog post, the researchers stated that numerous security flaws affected the app in different ways.
In brief, a successful attack required a perpetrator to first use SMS spoofing to send malicious links to the target. Clicking on the link would then exploit the ‘deep links’ functionality of Tiktok. This would subsequently allow the attacker to trigger an intent in the app via the browser URL.
Then, the malicious link would redirect the victim to a malicious website, opening the possibilities for cross-site scripting (XSS) attacks, cross-site request forgery (CSRF) attacks, and data exposure.
Some possible attack scenarios include deletion of videos from users’ accounts, adding videos to the account, or making private videos public. Moreover, the attacker could simply take control of the target account and gain access to the victim’s personal information.
The following video demonstrates how an adversary could exploit all the flaws for a successful attack.
https://research.checkpoint.com/wp-content/uploads/2020/01/tiktok_video.mp4
Let us know your thoughts in the comments.