TikTok caught secretly spying on millions of iPhone users

Apple iOS apps can read the last thing copied to clipboard

Apple recently fixed a bug in iOS 14 that allows apps to secretly access the clipboard on Apple devices. The new OS will warn users when an app reads the last item copied to the clipboard, but several apps have already been caught invading people’s privacy, including TikTok, according to security researchers Talal Haj Bakry and Tommy Mysk

China’s Bytedance, owner of TikTok, stated the problem is tied to an outdated advertising SDK. However, according to the clipboard warning in iOS 14 beta, TikTok is continuing to abuse users’ privacy.

A company spokesperson said it was “triggered by a feature designed to identify repetitive, spammy behavior.” TikTok submitted an updated version of the app without the anti-spam feature to the App Store.

The TikTok spokesperson added: “The clipboard access issues showed up due to third-party SDKs, in our case an older version Google Ads SDK, so we do not get access to the information through this. We are in the processes of updating so that the third-party SDK will no longer have access.” 

Changes to Apple’s iOS 14 security and privacy settings helped to identify TikTok and other apps secretly accessing the clipboard. The vulnerability meant anything copied on a user’s Mac or iPad could be read by active apps on their iPhone, including passwords, work documents, personal emails and financial documents.

Apple’s iOS fix will force TikTok and other companies to update their apps.

Apple initially ignored the clipboard vulnerability, eventually publishing a fix following media coverage of the security findings. According to Bakry and Mysk, “Apple dismissed the risks that we highlighted and explained that iOS already had mechanisms to counter all of the risks. But the mechanisms that Apple provided were not effective to protect user privacy.” 

iPhone users should update their TikTok app when the newest version is released.

Featured Resources

2021 Thales access management index: Global edition

The challenges of trusted access in a cloud-first world

Free download

Transforming higher education for the digital era

The future is yours

Free download

Building a cloud-native, hybrid-multi cloud infrastructure

Get ready for hybrid-multi cloud databases, AI, and machine learning workloads

Free download

The next biggest shopping destination is the cloud

Know why retail businesses must move to the cloud

Free Download

Recommended

Senators urge FTC to enforce child privacy laws
privacy

Senators urge FTC to enforce child privacy laws

8 Oct 2021
Are you over-sharing online?
social media

Are you over-sharing online?

1 Sep 2021
What is customer identity and access management? 
identity and access management (IAM)

What is customer identity and access management? 

19 Aug 2021
Pearson fined $1 million for downplaying severity of 2018 breach
data breaches

Pearson fined $1 million for downplaying severity of 2018 breach

17 Aug 2021

Most Popular

Best Linux distros 2021
operating systems

Best Linux distros 2021

11 Oct 2021
Veritas Backup Exec 21.3 review: Covers every angle
backup software

Veritas Backup Exec 21.3 review: Covers every angle

14 Oct 2021
HPE wins networking contract with Birmingham 2022 Commonwealth Games
Network & Internet

HPE wins networking contract with Birmingham 2022 Commonwealth Games

15 Oct 2021