Primary Country (Mandatory)

Other Country (Optional)

Set News Language for United States

Primary Language (Mandatory)
Other Language[s] (Optional)
No other language available

Set News Language for World

Primary Language (Mandatory)
Other Language(s) (Optional)

Set News Source for United States

Primary Source (Mandatory)
Other Source[s] (Optional)

Set News Source for World

Primary Source (Mandatory)
Other Source(s) (Optional)
  • Countries
    • India
    • United States
    • Qatar
    • Germany
    • China
    • Canada
    • World
  • Categories
    • National
    • International
    • Business
    • Entertainment
    • Sports
    • Special
    • All Categories
  • Available Languages for United States
    • English
  • All Languages
    • English
    • Hindi
    • Arabic
    • German
    • Chinese
    • French
  • Sources
    • India
      • AajTak
      • NDTV India
      • The Hindu
      • India Today
      • Zee News
      • NDTV
      • BBC
      • The Wire
      • News18
      • News 24
      • The Quint
      • ABP News
      • Zee News
      • News 24
    • United States
      • CNN
      • Fox News
      • Al Jazeera
      • CBSN
      • NY Post
      • Voice of America
      • The New York Times
      • HuffPost
      • ABC News
      • Newsy
    • Qatar
      • Al Jazeera
      • Al Arab
      • The Peninsula
      • Gulf Times
      • Al Sharq
      • Qatar Tribune
      • Al Raya
      • Lusail
    • Germany
      • DW
      • ZDF
      • ProSieben
      • RTL
      • n-tv
      • Die Welt
      • Süddeutsche Zeitung
      • Frankfurter Rundschau
    • China
      • China Daily
      • BBC
      • The New York Times
      • Voice of America
      • Beijing Daily
      • The Epoch Times
      • Ta Kung Pao
      • Xinmin Evening News
    • Canada
      • CBC
      • Radio-Canada
      • CTV
      • TVA Nouvelles
      • Le Journal de Montréal
      • Global News
      • BNN Bloomberg
      • Métro
TikTok can bypass Apple and Google security on phone and access full user data, researchers say

TikTok can bypass Apple and Google security on phone and access full user data, researchers say

India Today
Tuesday, February 15, 2022 05:06:26 AM UTC

A new report verifies two studies that map TikTok's source code to check its app behaviour and data collection practices. The deep dive raises a number of concerns that are now being flagged by cybersecurity experts.

Cybersecurity researchers have time and again raised red flags on the data collection practices followed by TikTok. Despite its continuously surging popularity, the short video app has often been blamed for infringing user privacy through its methods. Reiterating the same, a new report now mentions that the app is even able to bypass the security protocols put in place by the Google Play Store and the Apple App Store.

After verifying two studies conducted by “white hat” cybersecurity experts in November 2020 and January 2021, a new report by TheWrap cites the analysis of five independent experts to claim that TikTok is able to gain "an all-access pass to user data." For this, the report mentions that the app is able to avoid code audits on the app stores of Apple and Google, as well as change its behaviour intermittently to better utilise device tracking.

Deeming this "highly unusual," the report mentions that the behaviour largely exceeds that of other social media apps like Facebook and Twitter. One cybersecurity expert who reviewed the two “white hat” studies told TheWrap that the TikTok browser can convert from web to device, as well as "query things on the device itself.” This allows TikTok "carte blanche" access to a device.

Yet another expert told the publication that the app conceals its inner workings more than other social media networks and it is thus difficult to know the extent to which it can mine data from a device. It then becomes a question of trust, as even if the app is not doing anything bad today, does not mean it is not able to do so.

As mentioned in the report, the two studies found that TikTok’s source code uses device IDs that identify an individual device for ad integration. Once it shares this ID with advertisers, they are able to track people over time "across devices and installs."

The researchers also discovered that the app "essentially acts like a web browser." It uses a special JavaScript bridge that retrieves the app from TikTok’s servers as and when it is launched on a phone. In theory, this allows the TikTok app to change its behaviour dynamically, without pushing an update to users.

This makes it difficult to check the security of the app as the same cannot be figured by static analysis of the app.

Read full story on India Today
Share this story on:-
More Related News
© 2008 - 2025 Webjosh  |  News Archive  |  Privacy Policy  |  Contact Us