TikTok Flaw Lay Bare Phone Numbers, User IDs For Phishing Attacks
#1
Information 
Quote:A vulnerability in the popular TikTok short-form video-sharing platform could have allowed attackers to easily compile users’ phone numbers, unique user IDs and other data ripe for phishing attacks.
 
TikTok, owned by ByteDance, has more than 800 million active users worldwide. The vulnerability, which was reported and patched before its disclosure on Tuesday, existed in the “Find Friends” feature of the TikTok mobile app. This feature allows users to find their friends, either via their contacts, via Facebook or by inviting friends.
 
In order to help users find friends through their contacts, TikTok contained a sync feature for contacts who had TikTok accounts. That means that it is possible to connect profile details with phone numbers. Researchers said an attacker could leverage this feature in order to query TikTok’s entire database – potentially opening up for privacy violations.

“The vulnerability could have allowed an attacker to build a database of user details and their respective phone numbers,” said Oded Vanunu, head of products vulnerabilities research at Check Point. “An attacker with that degree of sensitive information could perform a range of malicious activities, such as spear phishing or other criminal actions.”

Read more: https://threatpost.com/tiktok-flaw-phish...ks/163322/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread:
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Waterfox 6.6.13
Waterfox 6.6.13 ...harlan4096 — 06:14
Subscription security: how to protect yo...
Why subscription o...harlan4096 — 06:10
Mozilla Firefox Browser 151.0
Mozilla Firefox Br...harlan4096 — 06:09
Tor Browser 15.0.14
Tor Browser 15.0.1...harlan4096 — 06:07
About that new SecureBoot folder in C:/W...
If you’ve noticed ...harlan4096 — 06:05

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>