DepthFirst reveals TikTok vulnerability allowing remote camera access

Summary

An employee from DepthFirst, a cybersecurity start-up, exploited a vulnerability in TikTok that allowed remote access to the camera and photo roll on a device using a free AI model. DepthFirst reported this issue to TikTok, which acknowledged the vulnerability and implemented a fix. This incident highlights the accessibility of certain Chinese-developed AI models that enable public usage for cybersecurity tasks, contrasting with the limitations set by some U.S. providers on similar applications.

Analysis

TikTok: TikTok is a global short-form video platform owned by ByteDance that runs on mobile apps incorporating third-party and open-source components. The news concerns a security flaw in its application that allowed remote device access when discovered via AI-assisted research. TikTok reviewed the disclosure from DepthFirst, confirmed the issue, and implemented a fix. DepthFirst: DepthFirst is an AI-focused cybersecurity startup founded in 2024 that builds specialized models and agentic systems for autonomous vulnerability discovery and validation in software. Its General Security Intelligence platform uses custom-trained AI to analyze codebases and workflows for security flaws that traditional tools might miss. In the reported incident, an employee used a modified free AI model to identify a vulnerability in TikTok's app, enabling a demonstration of remote camera and photo roll access on a browsing device. AI Model Accessibility: Certain Chinese-developed AI models permit free public download and modification for cybersecurity tasks, in contrast to restrictions imposed by some leading U.S. providers on similar use cases. Vulnerability Disclosure: TikTok promptly confirmed and resolved the camera and photo access vulnerability identified through AI-powered research in its mobile application.

Categories

tech

Related sources

View Original Tweet