QID 630810
Date Published: 2022-06-14
QID 630810: TikTok For Android Remote Code Execution (RCE) Vulnerability
The TikTok application before 23.8.4 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to CVE-2022-28799 to address this issue and obtain more information.
Vendor References
- CVE-2022-28799 -
nvd.nist.gov/vuln/detail/CVE-2022-28799
CVEs related to QID 630810
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-28799 | Android |
|