Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
Menu
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
  1. Home
  2. News
  3. Microsoft uncovers “high severity” Tiktok bug to take over user accounts, now patched – onmsft.com

Microsoft uncovers “high severity” Tiktok bug to take over user accounts, now patched – onmsft.com

Kevin Okemwa Kevin Okemwa
August 31, 2022
2 min read

Microsoft found a high-severity vulnerability in the TikTok Android application, which would have subjected users’ accounts to susceptibility with just a single click. Microsoft reached out to Tiktok pointing out the issue that has since been patched.

Microsoft discovered a high-severity vulnerability in the TikTok Android application that could have allowed attackers to compromise accounts with a single click. Learn more about CVE-2022-28799, which is now fixed, via our latest blog post: https://t.co/0PaWJ5cFYj

— Microsoft Security Intelligence (@MsftSecIntel) August 31, 2022

Through this loophole, attackers could have compromised the account of any Tiktok users running on Android version 23.7.3 and lower without them knowing. By clicking on this malicious link, the attackers would get primary access to the user’s account, thus allowing them to make changes and even post content on the platform. Once compromised, the user’s Tiktok bio would then be changed to “SECURITY BREACHED”.

Microsoft conducted an assessment to gauge the impact of this setback and found that both versions of Tiktok on Android were affected, that is, the one that serves East and Southeast Asia and the other one that serves the rest of the world. This translates to over 1.5 billion installations combined.

As per the blog post:

The vulnerability itself was ultimately found to reside in the app’s handling of a particular deeplink. In the context of the Android operating system, a deeplink is a special hyperlink that links to a specific component within a mobile app and consists of a scheme and (usually) a host part. When a deeplink is clicked, the Android package manager queries all the installed applications to see which one can handle the deeplink and then routes it to the component declared as its handler.

The deeplink handling does feature a verification process that essentially adds a layer of security which limits the activities that one can perform when an application loads on a given link. However, the attackers found a way to circumvent the verification process and be able to gain access to the app. They would then be able to access an authentication token linked to the user’s account.

Share This Post:

Share this article:
Tags:
Cybersecurity Microsoft TikTok
Previous Article Microsoft to hold “Stop Ransomware with Microsoft Security” digital event on September 15th – onmsft.com Next Article Refreshed Surface Keyboard, Mouse and Pen images hint at possible Studio update this Fall – onmsft.com

Related Articles

Chrome tests Google Drive file uploads in the AI Mode compose box

April 14, 2026
Gemini image creation using right click desktop Chrome

Chrome lets you remake images with Gemini on desktop using just a right-click

April 13, 2026
Samsung Display crosses 5 million QD-OLED monitor shipments as demand grows fast, with new panels and strong premium market expansion worldwide.

Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years

April 9, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Google Drive file uploads in the AI Mode compose box
  • Chrome lets you remake images with Gemini on desktop using just a right-click
  • Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years
  • Intel Arc Pro B70 Teardown Reveals Blower Cooler and Early Board Design Details
  • Users Modify RTX 5090 Lightning Z Hardware to Unlock MSI’s Restricted 2500W BIOS

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Google Drive file uploads in the AI Mode compose box
  • Chrome lets you remake images with Gemini on desktop using just a right-click
  • Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years
  • Intel Arc Pro B70 Teardown Reveals Blower Cooler and Early Board Design Details
  • Users Modify RTX 5090 Lightning Z Hardware to Unlock MSI’s Restricted 2500W BIOS

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy