Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft uncovers “high severity” Tiktok bug to take over user accounts, now patched – onmsft.com

Microsoft uncovers “high severity” Tiktok bug to take over user accounts, now patched – onmsft.com

Kevin Okemwa Kevin Okemwa
August 31, 2022
2 min read

Microsoft found a high-severity vulnerability in the TikTok Android application, which would have subjected users’ accounts to susceptibility with just a single click. Microsoft reached out to Tiktok pointing out the issue that has since been patched.

Microsoft discovered a high-severity vulnerability in the TikTok Android application that could have allowed attackers to compromise accounts with a single click. Learn more about CVE-2022-28799, which is now fixed, via our latest blog post: https://t.co/0PaWJ5cFYj

— Microsoft Security Intelligence (@MsftSecIntel) August 31, 2022

Through this loophole, attackers could have compromised the account of any Tiktok users running on Android version 23.7.3 and lower without them knowing. By clicking on this malicious link, the attackers would get primary access to the user’s account, thus allowing them to make changes and even post content on the platform. Once compromised, the user’s Tiktok bio would then be changed to “SECURITY BREACHED”.

Microsoft conducted an assessment to gauge the impact of this setback and found that both versions of Tiktok on Android were affected, that is, the one that serves East and Southeast Asia and the other one that serves the rest of the world. This translates to over 1.5 billion installations combined.

As per the blog post:

The vulnerability itself was ultimately found to reside in the app’s handling of a particular deeplink. In the context of the Android operating system, a deeplink is a special hyperlink that links to a specific component within a mobile app and consists of a scheme and (usually) a host part. When a deeplink is clicked, the Android package manager queries all the installed applications to see which one can handle the deeplink and then routes it to the component declared as its handler.

The deeplink handling does feature a verification process that essentially adds a layer of security which limits the activities that one can perform when an application loads on a given link. However, the attackers found a way to circumvent the verification process and be able to gain access to the app. They would then be able to access an authentication token linked to the user’s account.

Share This Post:

Share this article:
Tags:
Cybersecurity Microsoft TikTok
Previous Article Microsoft to hold “Stop Ransomware with Microsoft Security” digital event on September 15th – onmsft.com Next Article Refreshed Surface Keyboard, Mouse and Pen images hint at possible Studio update this Fall – onmsft.com

Related Articles

Chrome and Gemini icons representing Gemini Live voice assistant integration in Chrome

Chrome tests Gemini Live voice assistant in a floating overlay panel

March 14, 2026

Chrome’s Organizer feature may sync Gemini and AI conversations across devices

March 14, 2026

After Chrome, Edge tests launching the browser automatically when you sign into Windows

March 13, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy