TikTok caught secretly spying on millions of iPhone users

Apple iOS apps can read the last thing copied to clipboard

Apple recently fixed a bug in iOS 14 that allows apps to secretly access the clipboard on Apple devices. The new OS will warn users when an app reads the last item copied to the clipboard, but several apps have already been caught invading people’s privacy, including TikTok, according to security researchers Talal Haj Bakry and Tommy Mysk

China’s Bytedance, owner of TikTok, stated the problem is tied to an outdated advertising SDK. However, according to the clipboard warning in iOS 14 beta, TikTok is continuing to abuse users’ privacy.

A company spokesperson said it was “triggered by a feature designed to identify repetitive, spammy behavior.” TikTok submitted an updated version of the app without the anti-spam feature to the App Store.

The TikTok spokesperson added: “The clipboard access issues showed up due to third-party SDKs, in our case an older version Google Ads SDK, so we do not get access to the information through this. We are in the processes of updating so that the third-party SDK will no longer have access.” 

Changes to Apple’s iOS 14 security and privacy settings helped to identify TikTok and other apps secretly accessing the clipboard. The vulnerability meant anything copied on a user’s Mac or iPad could be read by active apps on their iPhone, including passwords, work documents, personal emails and financial documents.

Apple’s iOS fix will force TikTok and other companies to update their apps.

Apple initially ignored the clipboard vulnerability, eventually publishing a fix following media coverage of the security findings. According to Bakry and Mysk, “Apple dismissed the risks that we highlighted and explained that iOS already had mechanisms to counter all of the risks. But the mechanisms that Apple provided were not effective to protect user privacy.” 

iPhone users should update their TikTok app when the newest version is released.

Featured Resources

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Simplify cluster security at scale

Centralised secrets management across hybrid, multi-cloud environments

Download now

The endpoint as a key element of your security infrastructure

Threats to endpoints in a world of remote working

Download now

2021 state of IT asset management report

The role of IT asset management for maximising technology investments

Download now

Recommended

Instagram to extend livestreaming time limit to 4 hours
social media

Instagram to extend livestreaming time limit to 4 hours

28 Oct 2020
Cisco finds an increase in security concerns due to remote working
Security

Cisco finds an increase in security concerns due to remote working

21 Oct 2020
New chatbot and nano influencer services help online sellers
social media marketing

New chatbot and nano influencer services help online sellers

15 Oct 2020
Mozilla and Brave release one-click method for online privacy requests
web browser

Mozilla and Brave release one-click method for online privacy requests

7 Oct 2020

Most Popular

Do smart devices make us less intelligent?
artificial intelligence (AI)

Do smart devices make us less intelligent?

19 Oct 2020
Politicians need to stop talking about technology
Policy & legislation

Politicians need to stop talking about technology

21 Oct 2020
Best MDM solutions 2020
mobile device management (MDM)

Best MDM solutions 2020

21 Oct 2020