a huge loophole allows hackers to access your personal data

2023-05-08 11:02:10

Imperva cybersecurity researchers have discovered a serious security flaw within TikTok, which allows hackers using it to steal a lot of personal data from their victims. To do this, they simply need to send a private message via the web version of the Chinese application.

Credit: sasha85ru/123RF

If you visit TikTok regularly, we strongly advise you to update the application. Indeed, the latest study from the cybersecurity firm Imperva sends shivers down the spine. According to experts, a major security breach has allowed hackers to steal a large amount of personal data in the simplest way possible. Indeed, they only had to send a private message to their target via the web version of the application.

More specifically, it was necessary to go through the PostMessage API, which made it possible to override the security measures integrated by TikTok. In this way, the messaging system analyzes the message in question, without identifying the threat that has slipped into it. Once the victim has taken the bait, all the hackers have to do is make their deal. According to Imperva, this method allowed them to access a lot of confidential sensitive data.

Related — TikTok is fighting misinformation by deleting climate skeptics’ videos today

TikTok users victim of a serious security breach

Imperva researchers explain that the hackers collected a lot of confidential information related to their victims’ accounts, such as the videos viewed, the time spent on each video and various other data from their profiles. But other types of data were also stolen, such as the type of device used, the operating system as well as the searches carried out on the application.

In other words, all this data can be used by hackers to impersonate the targeted person and, from there, commit a number of misdeeds. Dissemination of scams, blackmail, we pass and the best. If this has not yet been done, we strongly advise you to download the latest TikTok update, which corrects this vulnerability.

Source : Imperva

1683544890
#huge #loophole #hackers #access #personal #data

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.