TikTok has some worrying security flaws that could leave your activity open to anyone – TechToday

Cybersecurity researchers at Imperva have discovered a flaw in the popular social media app TikTok that could have allowed threat actors to extract sensitive data from victims’ devices for use in identity theft, phishing or blackmail

The vulnerability, which has since been patched, was found in the way the app handled incoming messages. Explaining the method, the researchers said that attackers could send a malicious message to the TikTok web app through the PostMessage API, which would bypass any security measures.

