Most Viewed Content:

Microsoft working on new features for Win11 / Win12: smart notifications, depth-of-field effects

According to the source Albacore (@thebookisclosed), Microsoft is preparing...

Toyota responds to continued production cuts in the next 3 months: easing pressure on dealer earnings

In response to the news that "production will continue...

India’s censorship body gave power to remove pirated Movies from platforms

India’s Ministry of Information and Broadcasting announced that its...

TikTok company spokesperson denies Javascript code is used for malicious behavior

According to security researcher Felix Krause, TikTok’s custom in-app browser on iOS injects JavaScript code into external websites, allowing TikTok to monitor “all keyboard input and clicks” when users interact with a given website, but TikTok has reportedly denied that the code was used for malicious behavior.

According to security researcher Felix Krause, TikTok’s custom in-app browser on iOS injects JavaScript code into external websites, allowing TikTok to monitor “all keyboard input and clicks” when users interact with a given website, but TikTok has reportedly denied that the code was used for malicious behavior.

Krause said the browser within the TikTok App “subscribes” to all keyboard input, including any sensitive details such as passwords and credit card information, as well as every click on the screen, when users interact with external websites.

“From a technical perspective, this is the equivalent of installing a keylogger on a third-party website,” Krause wrote of the JavaScript code injected into TikTok. However, the researchers added that “the mere fact that the app injects JavaScript into an external website does not mean that the app is doing anything malicious.”

In a statement shared with Forbes, a TikTok spokesperson acknowledged the faulty JavaScript code, but said it was only used for debugging, troubleshooting and performance monitoring to ensure “the best user experience.”

“As with other platforms, we use the in-app browser to provide the best user experience, but the Javascript code in question is only used for debugging, troubleshooting and performance monitoring — for example, to check page load speeds or if it crashes.”

Krause said that users who want to protect themselves from any potentially malicious use of in-app browser JavaScript code should switch to using the platform’s default browser access to view a given link whenever possible, such as Safari on iPhone and iPad.

According to Krause, Facebook and Instagram are two other problematic applications that insert JavaScript code into external websites that are loaded in the in-app browser, allowing the apps to track user activity. A spokesperson for Facebook and Instagram parent company Meta said in a tweet that the company “intentionally developed this code to respect people’s app tracking transparency (ATT) choices on our platform. Meta Instagram violated Apple’s iOS Privacy Policy when it was revealed that it tracked users’ web activity through an in-app browser.

Krause said he created simple tools that allow anyone to check if the in-app browser is injecting JavaScript code when presenting a website. Users simply open the app they want to analyze, share the address InAppBrowser.com somewhere within the app (for example, by sending a message directly to another person), click on the link within the app to be in the -app browser, and read the details of the displayed report, the researchers said.

Apple did not immediately respond to a request for comment.

A further statement from a TikTok spokesperson said that

"The report's conclusions about TikTok are incorrect and misleading. The researchers clearly state that the JavaScript code does not imply that our application is doing anything malicious and acknowledge that they have no way of knowing what kind of data is being collected by the browser within our application. We do not collect keystrokes or text input through this code, which is used only for debugging, troubleshooting and performance monitoring."

According to a TikTok spokesperson, the JavaScript code is part of a software development kit (SDK) being utilized by TikTok, and the “keypress” and “keydown” functions mentioned by Krause are common inputs that TikTok does not use for keystroke recording.

Latest

2024 Beijing Auto Show: Aion Y Plus new colors unveiled

At the 2024 Beijing Auto Show, the Aion brand...

OPPO Find X7 White phone opens for pre-sale, starting at 3899 RMB

The OPPO Find X7 white phone is now available...

Official spy photos of Lynk & Co ZERO pure electric sedan released

The deputy general manager of Lynk & Co Auto...

OPPO Find X7 Ultra satellite communication edition adds 16GB+ 512GB, priced at 6799 RMB

The OPPO Find X7 Ultra satellite communication version will...

Newsletter

Don't miss

2024 Beijing Auto Show: Aion Y Plus new colors unveiled

At the 2024 Beijing Auto Show, the Aion brand...

OPPO Find X7 White phone opens for pre-sale, starting at 3899 RMB

The OPPO Find X7 white phone is now available...

Official spy photos of Lynk & Co ZERO pure electric sedan released

The deputy general manager of Lynk & Co Auto...

OPPO Find X7 Ultra satellite communication edition adds 16GB+ 512GB, priced at 6799 RMB

The OPPO Find X7 Ultra satellite communication version will...

Honda Plans Electric Vehicle Supply Chain Project in Canada: 240K Annual Capacity

Honda recently announced plans to build an electric vehicle...
Threza Gabriel
Threza Gabrielhttps://www.techgoing.com
Threza Gabriel is a news writer at TechGoing. TechGoing is a global tech media to brings you the latest technology stories, including smartphones, electric vehicles, smart home devices, gaming, wearable gadgets, and all tech trending.

2024 Beijing Auto Show: Yuanhang H9 officially starts pre-sales

During the 2024 Beijing Auto Show, the new large SUV Yuanhang H9 officially opened for pre-sale. The pre-sale price of this car is 409,800-439,800...

Audi SQ6 e-tron debuts at the 2024 Beijing Auto Show

At the 2024 Beijing Auto Show, the Audi SQ6 e-tron model made its domestic debut. The car plans to enter the Chinese market as...

BYD Hiace 07 EV interior official images released: With high-end smart driving

BYD today announced the official interior image of its new model Hiace 07EV, which has smart curves that "outline the beauty of the ocean"...