CHKP Check Point Software Technologies Ltd.

Check Point Research Reveals Multiple Vulnerabilities in TikTok

Check Point Research Reveals Multiple Vulnerabilities in TikTok

Personal information such as private addresses and email addresses were vulnerable to exposure in one of the world’s most trending apps

SAN CARLOS, Calif., Jan. 08, 2020 (GLOBE NEWSWIRE) -- Check Point Research, the Threat Intelligence arm of (NASDAQ: CHKP), a leading provider of cyber security solutions globally, revealed today that it uncovered multiple vulnerabilities in TikTok that could have allowed attacks to manipulate content on user accounts and even extract confidential personal information saved on these accounts.

TikTok is used mainly by teenagers and kids that use this app to share, save and keep private (and sometimes very sensitive) videos of themselves and their loved ones. The research found that an attacker could send a spoofed SMS message to a user containing a malicious link. When the user clicked on the malicious link, the attacker was able to get a hold of the TikTok account and manipulate its content by deleting videos, uploading unauthorized videos, and making private or "hidden" videos public.

The research also found that Tiktok's subdomain was vulnerable to XSS attacks, a type of attack in which malicious scripts are injected into otherwise benign and trusted websites. Check Point researchers leveraged this vulnerability to retrieve personal information saved on user accounts including private email addresses and birthdates.

Check Point Research informed TikTok developers of the vulnerabilities exposed in this research and a fix was responsibly deployed to ensure its users can safely continue using the TikTok app.

“Data is pervasive but data breaches are becoming an epidemic, and our latest research shows that the most popular apps are still at risk,” said Oded Vanunu, Check Point’s Head of Product Vulnerability Research. “Social media applications are highly targeted for vulnerabilities as they provide a good source for private data and offer a good attack surface gate. Malicious actors are spending large amounts of money and putting in great effort to penetrate into such huge applications. Yet most users are under the assumption that they are protected by the app they are using.”

Luke Deshotels, PhD, TikTok Security Team: “TikTok is committed to protecting user data. Like many organizations, we encourage responsible security researchers to privately disclose zero day vulnerabilities to us. Before public disclosure, CheckPoint agreed that all reported issues were patched in the latest version of our app. We hope that this successful resolution will encourage future collaboration with security researchers."

Available in over 150 markets, used in 75 languages globally, and with over 1 billion users, TikTok is definitely one of the most downloaded apps around. As of October 2019, TikTok is the most downloaded app in the United States, making it the first Chinese app to have achieved such a record.

on the research is available on the Check Point Research blog.

Follow Check Point Research via:

Blog:

Twitter:

About Check Point Research

Check Point Research provides leading cyber threat intelligence to Check Point Software customers and the greater intelligence community. The research team collects and analyzes global cyber-attack data stored on ThreatCloud to keep hackers at bay, while ensuring all Check Point products are updated with the latest protections. The research team consists of over 100 analysts and researchers cooperating with other security vendors, law enforcement and various CERTs.

About Check Point Software Technologies Ltd.

Check Point Software Technologies Ltd. () is a leading provider of cyber security solutions to governments and corporate enterprises globally.  Check Point’s solutions protect customers from 5th generation cyber-attacks with an industry leading catch rate of malware, ransomware and advanced targeted threats. Check Point offers a multilevel security architecture, “Infinity Total Protection with Gen V advanced threat prevention”, this combined product architecture defends an enterprise's cloud, network and mobile devices. Check Point provides the most comprehensive and intuitive one point of control security management system. Check Point protects over 100,000 organizations of all sizes.

MEDIA CONTACT:                                                          

Jacinta Paul                                                               

Check Point Software Technologies                                       

                                                            

                                              

INVESTOR CONTACT:   

Kip E. Meintzer

Check Point Software Technologies              

+1 650.628.2040

EN
08/01/2020

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Check Point Software Technologies Ltd.

Anish Jog ... (+4)
  • Anish Jog
  • Daniel Ives
  • Sam Brandeis
  • Steven Wahrhaftig
 PRESS RELEASE

Check Point Software’s 2026 Cyber Security Report Shows Global Attacks...

Check Point Software’s 2026 Cyber Security Report Shows Global Attacks Reach Record Levels as AI Accelerates the Threat Landscape Organizations face nearly 2,000 cyber attacks per week as attackers combine automation, AI, and social engineering across multiple channels REDWOOD CITY, Calif., Jan. 28, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: CHKP), a pioneer and global leader in cyber security solutions, today released its Cyber Security Report 2026, the company’s 14th annual analysis of global cyber attack trends. The report reveals that organizations experienced an average of 1,968 cyber att...

 PRESS RELEASE

Check Point Software Technologies and Hendrick Motorsports Partner to ...

Check Point Software Technologies and Hendrick Motorsports Partner to Strengthen Cyber Security for Racing Operations NASCAR’s winningest team will secure its digital operations across external risk, email, cloud, and network environments REDWOOD CITY, Calif. & CONCORD, N.C., Jan. 27, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: CHKP), a pioneer and global leader in cyber security solutions, today announced a new official partnership with NASCAR powerhouse Hendrick Motorsports and its No. 17 Chevrolet team to enhance the organization’s cyber defenses and protect its technology ecosystem against e...

 PRESS RELEASE

Check Point Introduces AI-Driven Exposure Management to Close the Cybe...

Check Point Introduces AI-Driven Exposure Management to Close the Cyber Security Remediation Gap Designed for AI-era attacks, Exposure Management helps organizations reduce risk faster using existing security controls REDWOOD CITY, Calif., Jan. 21, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: CHKP), a pioneer and global leader in cyber security solutions, today announced Check Point Exposure Management, a new approach designed to help organizations defend against AI-era attacks by turning fragmented exposure data into prioritized, actionable, and safe remediation. Powered by Cyberint, Veriti, an...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch