In-App TikTok Browser Security Concerns

According to PCMag Security Watch, a researcher recently discovered that TikTok's in-app browser injects JavaScript into external websites, causing potential security risks. This is just the latest security problem for the social media giant, which is still facing scrutiny from US lawmakers after leaked audio revealed the video hosting service may have been sharing US user data with China.

TikTok is owned by a Chinese company. Given the political tension between the two countries, it's unsurprising that many US-based news media outlets jumped at the chance to report on security researcher Felix Krause's findings. On his website, Krause says his tests show that when a user opens a webpage inside TikTok's iOS app, the in-app browser injects a code that subscribes to all keyboard inputs and every tap on the screen. Krause states, "We can’t know what TikTok uses the subscription for, but from a technical perspective, this is the equivalent of installing a keylogger on third-party websites." 

A TikTok spokesperson admitted the app injects JavaScript into websites but insisted, "Contrary to the report's claims, we do not collect keystroke or text inputs through this code, which is solely used for debugging, troubleshooting, and performance monitoring."

Read the entire article here


Popular posts from this blog

EOQ Calculations in Excel

Reliability Calculations in Excel

“How Are We Doing?” Efficiency, Utilization, and Productivity