DepthFirst reveals TikTok vulnerability allowing remote camera access
Summary
An employee from DepthFirst, a cybersecurity start-up, exploited a vulnerability in TikTok that allowed remote access to the camera and photo roll on a device using a free AI model. DepthFirst reported this issue to TikTok, which acknowledged the vulnerability and implemented a fix. This incident highlights the accessibility of certain Chinese-developed AI models that enable public usage for cybersecurity tasks, contrasting with the limitations set by some U.S. providers on similar applications.
Analysis
TikTok: TikTok is a global short-form video platform owned by ByteDance that runs on mobile apps incorporating third-party and open-source components. The news concerns a security flaw in its application that allowed remote device access when discovered via AI-assisted research. TikTok reviewed the disclosure from DepthFirst, confirmed the issue, and implemented a fix. DepthFirst: DepthFirst is an AI-focused cybersecurity startup founded in 2024 that builds specialized models and agentic systems for autonomous vulnerability discovery and validation in software. Its General Security Intelligence platform uses custom-trained AI to analyze codebases and workflows for security flaws that traditional tools might miss. In the reported incident, an employee used a modified free AI model to identify a vulnerability in TikTok's app, enabling a demonstration of remote camera and photo roll access on a browsing device. AI Model Accessibility: Certain Chinese-developed AI models permit free public download and modification for cybersecurity tasks, in contrast to restrictions imposed by some leading U.S. providers on similar use cases. Vulnerability Disclosure: TikTok promptly confirmed and resolved the camera and photo access vulnerability identified through AI-powered research in its mobile application.
Categories
tech
Related sources
- https://depthfirst.com/research/dfs-large-new-model-release
- https://siliconangle.com/2026/01/14/depthfirst-secures-40m-expand-agentic-approach-software-security/
- https://www.forbes.com/sites/thomasbrewster/2026/03/31/depthfirst-ai-cybersecurity-startup-580-million-valuation/
- https://depthfirst.com/post/almanax-is-joining-depthfirst
- https://g1.globo.com/tecnologia/noticia/2026/09/18/usuario-do-tiktok-tem-camera-e-fotos-acessadas-em-ataque-com-ajuda-de-ia.ghtml
- https://www.washingtonpost.com/technology/2026/09/18/cybersecurity-experts-say-free-ai-software-is-supercharging-hackers/
- https://techcrunch.com/2026/01/14/ai-security-firm-depthfirst-announces-40-million-series-a/
- https://aiweekly.co/alerts/depthfirst-finds-21-ffmpeg-zero-days-for-1000
- https://www.seattletimes.com/business/they-hacked-a-tiktok-users-camera-with-help-from-free-ai/
- https://runtimewire.com/article/depthfirst-dfs-large1-cybersecurity-model-vulnerability-detection
- https://www.securityweek.com/depthfirst-raises-80-million-in-series-b-funding/
- https://depthfirst.com/research/behind-the-gitlab-rce-a-depthfirst-journey-into-the-ruby-ecosystem