Beware! TikTok injects code into third party websites- Know how

Image Source : PIXABAY Tiktok TikTok, a Chinese short-form video app could be monitoring all keyboard inputs and taps via its in-app browser on iOS, reported an independent cyber-security researcher as a warning. Felix Krause, Founder of Fastlane which was acquired by Google, said that when the user opens any link on […]

Tiktok,
Image Source : PIXABAY Tiktok

TikTok, a Chinese short-form video app could be monitoring all keyboard inputs and taps via its in-app browser on iOS, reported an independent cyber-security researcher as a warning.

Felix Krause, Founder of Fastlane which was acquired by Google, said that when the user opens any link on the TikTok iOS app, it’s opened inside their in-app browser.

“While you are interacting with the website, TikTok subscribes to all keyboard inputs (including passwords, credit card information, etc.) and every tap on the screen, like which buttons and links you click,” Krause claimed in a blog post on Thursday.

TikTok iOS subscribes to every keystroke (text inputs) happening on third-party websites rendered inside the TikTok app, he said.

“This can include passwords, credit card information and other sensitive user data,” Krause added.

From a technical perspective, this is the equivalent of installing a keylogger on third-party websites.

The company confirmed those features exist in the code but said it is not using them on its in-app browser on the iOS app.

“Like other platforms, we use an in-app browser to provide an optimal user experience, but the Javascript code in question is used only for debugging, troubleshooting and performance monitoring of that experience – like checking how quickly page loads or whether it crashes,” a company spokesperson was quoted as saying in a Forbes report.

According to the researcher, it proves that “TikTok injects code into third party websites through their in-app browsers that behaves like a keylogger. However, claims it’s not being used”.

“This was an active choice the company made. This is a non-trivial engineering task. This does not happen by mistake or randomly,” he mentioned.

Inputs from IANS

Latest Technology News

Next Post

Half of Teens Say they Use Internet Nearly all the Time

Sun Aug 21 , 2022
New research suggests that nearly half of American teenagers say they use the internet “almost constantly.” The United States-based Pew Research Center released a study this month. It found that the share of teens who say they are online almost all the time rose from 24 percent in 2015 to […]