Microsoft reveals a now-patched “high severity vulnerability” in TikTok for Android that could let attackers take over accounts that clicked on a malicious link
The TikTok application before 23.7.3 for Android allows account takeover. Katie McCafferty / Microsoft Security Blog : Vulnerability in TikTok Android app could lead to one-click account hijacking Theo Wayt / New York Post : ‘High severity’: TikTok security flaw put hundreds of millions at hacking risk Vilius Petkauskas / Cybernews.com : Severe TikTok Android app flaw allowed account hijacking Sofia Wyciślik-Wilson / BetaNews : Microsoft undercovers high severity vulnerability which could allow one-click hijacking of TikTok accounts Sergiu Gatlan / BleepingComputer : Microsoft found TikTok Android flaw that let hackers hijack accounts Vish Gain / Silicon Republic : How to stay safe and avoid scams while scrolling through TikTok Kimberly Gedeon / Laptop Mag : TikTok terror! Severe bug allowed hackers to hijack accounts with just one click Davey Winder / Forbes : TikTok Account Takeover App Hack Only Needed 1 Click, Microsoft Says Livemint : Microsoft spots TikTok bug that could expose private videos of millions Luke Jones / WinBuzzer : TikTok Had a High Severity Bug That Allows One-Click Account Breaches Ravie Lakshmanan / The Hacker News : Microsoft Discover Severe ‘One-Click’ Exploit for TikTok Android App Sharron Bennet / MSPoweruser : Microsoft saves TikTok users after reporting vulnerability leading to “one-click account hijacking” Tweets: @msftsecintel : Microsoft discovered a high-severity vulnerability in the TikTok Android application that could have allowed attackers to compromise accounts with a single click. Learn more about CVE-2022-28799, which is now fixed, via our latest blog post: https://www.microsoft.com/... Ann Johnson / @ajohnsocyber : Ecosystem is the key to cyber success. After carefully reviewing the implications, a Microsoft security researcher notified TikTok of the issues in Feb 2022, as part of our responsible disclosure policy https://www.microsoft.com/...
Context & Ripple Effects
TikTok had already addressed major flaws affecting content, private videos, and personal data and a separate issue exposing users’ private information. Microsoft’s February 2022 responsible disclosure adds a one-click Android account-takeover route to that record, with TikTok responding through version 23.7.3.
The later reports of accounts targeted through a zero-day opened in a DM and a subsequent patched DM-based hijacking flaw show that malicious-message account compromise remained a recurring security concern for the platform.
First-order effects
- TikTok Android users on versions before 23.7.3 need the update to remove CVE-2022-28799’s malicious-link account-takeover path.
- Microsoft’s disclosure makes TikTok’s patch cycle and Android app-link handling a visible security issue for users and the platform’s security team.
Second-order effects
- TikTok must treat link and message entry points as repeat attack surfaces, rather than isolated defects, given the later DM-based account-hijacking vulnerability it also patched.
- Brands and high-profile accounts using TikTok face stronger incentives to keep mobile clients updated, because an account takeover can turn a user-targeted flaw into a channel-control problem.
Third-order effects
- Repeated fixes across private-data exposure, link-triggered takeover, and DM-triggered takeover point toward closed-loop mobile application security: faster disclosure, patch adoption, and retesting of adjacent user-input flows.
- If this pattern persists, platform security will be judged less by any single patch than by whether recurring account-compromise routes are eliminated across Android’s interaction surfaces.
The trend: TikTok’s security arc reflects a broader shift toward continuous mobile-app defense around the links and messages that connect users to account-sensitive actions.