TikTok behebt Zero-Day-Bug, mit dem hochkarätige Konten gekapert wurden

Teilen:

Over the past week, attackers have hijacked high-profile TikTok accounts belonging to multiple companies and celebrities, exploiting a zero-day vulnerability in the social media’s direct messages feature.

Zero-day vulnerabilities are security flaws with no official patch or public information detailing the underlying weakness.

After being compromised, user accounts belonging to Sony, CNN, and others had to be taken down to prevent abuse. CNN’s account was the first to be hijacked last week, as Semaphor first reported on Sunday.

As Forbes reported today, the exploit used by the attackers to hack the accounts via DMs only needs the targets to open the malicious message and doesn’t require downloading a payload or clicking embedded links.

“Our security team is aware of a potential exploit targeting a number of high-profile accounts,” TikTok spokesperson Jason Grosse told BleepingComputer.

“We have taken measures to stop this attack and prevent it from happening in the future. We’re working directly with affected account owners to restore access, if needed.”

According to Grosse, the attackers have only compromised a “small number” of TikTok accounts, according to “initial analysis.” The company has yet to reveal the exact number of impacted users and has not shared any details regarding the exploited vulnerability until the underlying flaw is fixed.

Not the first flaw allowing account takeovers

This isn’t the first vulnerability to impact TikTok users in recent years. Most recently, the company patched an Android app flaw discovered by Microsoft in August 2022 that let hackers “quickly and quietly” take over accounts with one tap.

Previously, it fixed security bugs that allowed attackers to bypass the platform’s privacy protections and steal private user information, including phone numbers and user IDs.

The company also fixed vulnerabilities that enabled threat actors to hijack the accounts of users who signed up via third-party apps and compromise accounts to manipulate the owners’ videos and steal their personal information.

TikTok surpassed 1 billion users in September 2021, and it currently has over 1 billion downloads on Google’s Play Store and 17 million ratings on the iOS App Store.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:08 pm, März 16, 2025
Wetter-Symbol 8°C
L: 7° | H: 10°
wenige Wolken
Luftfeuchtigkeit: 57 %
Druck: 1025 mb
Wind: 10 mph ENE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:12 am
Sonnenuntergang: 6:06 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 10°°C 0 mm 0% 11 mph 77 % 1027 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 10 mph 89 % 1029 mb 0 mm/h
Di. März 18 9:00 pm
Wetter-Symbol
4° | 10°°C 0 mm 0% 12 mph 78 % 1027 mb 0 mm/h
Mi. März 19 9:00 pm
Wetter-Symbol
3° | 15°°C 0 mm 0% 7 mph 79 % 1022 mb 0 mm/h
Do. März 20 9:00 pm
Wetter-Symbol
8° | 14°°C 0 mm 0% 7 mph 78 % 1021 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
9° | 10°°C 0 mm 0% 11 mph 52 % 1025 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 8 mph 60 % 1025 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 77 % 1027 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 6 mph 84 % 1027 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 7 mph 89 % 1027 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 7 mph 81 % 1028 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 7 mph 66 % 1029 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 8 mph 52 % 1028 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€75,837.53
-1.78%
Ethereum(ETH)
€1,725.71
-2.23%
Fesseln(USDT)
€0.92
-0.01%
XRP(XRP)
€2.12
-5.18%
Solana(SOL)
€118.89
-3.35%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.154185
-3.98%
Shiba Inu(SHIB)
€0.000012
-0.06%
Pepe(PEPE)
€0.000006
-4.79%
Peanut das Eichhörnchen(PNUT)
€0.189019
20.47%
Nach oben scrollen