In-App TikTok Browser Security Concerns
TikTok is owned by a Chinese company. Given the political tension between the two countries, it's unsurprising that many US-based news media outlets jumped at the chance to report on security researcher Felix Krause's findings. On his website, Krause says his tests show that when a user opens a webpage inside TikTok's iOS app, the in-app browser injects a code that subscribes to all keyboard inputs and every tap on the screen. Krause states, "We can’t know what TikTok uses the subscription for, but from a technical perspective, this is the equivalent of installing a keylogger on third-party websites."
A TikTok spokesperson admitted the app injects JavaScript into websites but insisted, "Contrary to the report's claims, we do not collect keystroke or text inputs through this code, which is solely used for debugging, troubleshooting, and performance monitoring."
Read the entire article here