Thứ Hai, Tháng Một 30, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

Microsoft Discover ‘One-Click’ Serious Exploit For Android TikTok App

1 Tháng Chín, 2022
in Tech
0
Microsoft Discover ‘One-Click’ Serious Exploit For Android TikTok App
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

Microsoft

On Wednesday, Microsoft disclosed details of a now-patched “high severity vulnerability” in the TikTok for Android app that could allow attackers to take over an account when a victim clicks on a malicious link.

Dimitrios Valsamaras of the Research Group Microsoft “Attackers could have taken advantage of the vulnerability to take over accounts without the user’s awareness if the targeted user simply clicked on a specially crafted link,” 365 Defender said.

Successful exploitation of this vulnerability could have allowed bad actors to access and modify TikTok profiles and sensitive user information, resulting in unauthorized disclosure of private videos. Attackers could also have abused this bug to send messages and upload videos on behalf of users.

The issue, which is resolved in version 23.7.3, affects two versions of the Android app com.ss.android.ugc.trill (for East and Southeast Asian users) and com.zhiliaoapp.musical (for East and Southeast Asian users) with users in other countries, except India, where it is banned). Combined, the apps have over 1.5 billion installs between them.

TikTok Android App

Tracked as CVE-2022-28799 (CVSS score: 8.8), the vulnerability concerns the application’s handling of what is known as deep linka special hyperlink that allows an application to open a specific resource in another application installed on the device, rather than the user directly entering a web page.

“A manually generated URL (unauthenticated deep link) can force com.zhiliaoapp.mus which is usually WebView to load an arbitrary web page,” according to the advisory for the vulnerability. “This could allow an attacker to take advantage of the attached JavaScript interface for a one-click takeover.”

TikTok Android App

Simply put, this vulnerability can circumvent application restrictions to deny untrusted servers and load any web page of the attacker’s choice through Android System WebView, a powerful engine. mechanism to display web content over other applications.

“The filtering takes place on the server side and the decision to load or reject a URL is based on the response received from a particular HTTP GET request,” explains Valsamaras, adding static analysis “indicating that it is possible to drop via server -check side-by-side by adding two additional parameters to the deeplink. “

The consequence of this exploit designed to hijack WebView to load fake web pages is that it could allow an adversary to call out more than 70 exposed TikTok endpoints, compromising the integrity of the user’s profile. users effectively. There is no evidence that the beetle has been weaponized in the wild.

“From a programming perspective, the use of JavaScript interfaces involves significant risks,” Microsoft notes. “A compromised JavaScript interface could allow an attacker to execute code using the application’s ID and privileges.”

.

Previous Post

The Hottest Live Stream Apps Earn Dollars Today

Next Post

Reduce lag, speed up gaming with NoPing

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
Reduce lag, speed up gaming with NoPing

Reduce lag, speed up gaming with NoPing

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem