Security Researchers Take Advantage of Insecure HTTP to Display Fake Videos on TikTok

An investigation by Talal Haj Bakry and Tommy Mysk has revealed that backwards-compatible support for HTTP in iOS and Android is allowing data from popular apps such as TikTok to be intercepted and altered.

tiktok logo
While most apps have made the transition to HTTPS, the research discovered that TikTok on iOS and Android still uses unencrypted HTTP to download media content. Consequently, TikTok inherits all of the known and well-documented HTTP vulnerabilities.

Apple introduced App Transport Security in iOS 9, requiring all HTTP connections to use encrypted HTTPS. Google similarly changed the default network security configuration in Android Pie to block all plaintext HTTP traffic. HTTP vulnerabilities still exist, however, since Apple and Google continue provide a way for developers to opt-out of HTTPS for backwards-compatibility.


The investigation proved that it is possible to successfully intercept TikTok traffic and fool the app to show fake videos as if they were published by popular and verified accounts. Any router between the TikTok app and TikTok's servers can easily expose a user's watch history, and change profile photos and videos. While only users connected to the router will see the malicious content, the research suggests that if a popular DNS server was hacked to include a corrupt DNS record, media data could be changed on a large scale.

Popular Stories

iphone 17 models

No iPhone 18 Launch This Year, Reports Suggest

Thursday January 1, 2026 8:43 am PST by
Apple is not expected to release a standard iPhone 18 model this year, according to a growing number of reports that suggest the company is planning a significant change to its long-standing annual iPhone launch cycle. Despite the immense success of the iPhone 17 in 2025, the iPhone 18 is not expected to arrive until the spring of 2027, leaving the iPhone 17 in the lineup as the latest...
duolingo ad live activity

Duolingo Used iPhone's Dynamic Island to Display Ads, Violating Apple Design Guidelines

Friday January 2, 2026 1:36 pm PST by
Language learning app Duolingo has apparently been using the iPhone's Live Activity feature to display ads on the Lock Screen and the Dynamic Island, which violates Apple's design guidelines. According to multiple reports on Reddit, the Duolingo app has been displaying an ad for a "Super offer," which is Duolingo's paid subscription option. Apple's guidelines for Live Activity state that...
Clicks Communicator Feature

'Clicks Communicator' Unveiled — Will You Carry This With Your iPhone?

Friday January 2, 2026 6:35 am PST by
The company behind the BlackBerry-like Clicks Keyboard accessory for the iPhone today unveiled a new Android 16 smartphone called the Clicks Communicator. The purpose-built device is designed to be used as a second phone alongside your iPhone, with the intended focus being communication over content consumption. It runs a custom Android launcher that offers a curated selection of messaging...
Low Cost MacBook Feature A18 Pro

Low-Price 12.9-Inch MacBook With A18 Pro Chip Reportedly Launching Early This Year

Friday January 2, 2026 9:08 am PST by
Apple plans to introduce a 12.9-inch MacBook in spring 2026, according to TrendForce. In a press release this week, the Taiwanese research firm said this MacBook will be aimed at the entry-level to mid-range market, with "competitive pricing." TrendForce did not share any further details about this MacBook, but the information that it shared lines up with several rumors about a more...
Low Cost A18 Pro MacBook Feature Pink

Apple's 2026 Low-Cost A18 Pro MacBook: What We Know So Far

Friday January 2, 2026 4:33 pm PST by
Apple is planning to release a low-cost MacBook in 2026, which will apparently compete with more affordable Chromebooks and Windows PCs. Apple's most affordable Mac right now is the $999 MacBook Air, and the upcoming low-cost MacBook is expected to be cheaper. Here's what we know about the low-cost MacBook so far. Size Rumors suggest the low-cost MacBook will have a display that's around 13 ...
Apple Fitness Plus hero

Apple Announces New Fitness+ Workout Programs, Strava Challenge, and More

Friday January 2, 2026 6:43 am PST by
Apple today announced a number of updates to Apple Fitness+ and activity with the Apple Watch. The key announcements include: New Year limited-edition award: Users can win the award by closing all three Activity Rings for seven days in a row in January. "Quit Quitting" Strava challenge: Available in Strava throughout January, users who log 12 workouts anytime in the month will win an ...
Mac Pro Feature Blue

What's Happening With the Mac Pro?

Wednesday December 31, 2025 9:59 am PST by
Apple hasn't updated the Mac Pro since 2023, and according to recent rumors, there's no update coming in the near future. In fact, Apple might be finished with the Mac Pro. Bloomberg recently said that the Mac Pro is "on the back burner" and has been "largely written off" by Apple. Apple apparently views the more compact Mac Studio as the ideal high-end pro-level desktop, and it has almost...

Top Rated Comments

patent10021 Avatar
75 months ago
The Leslie Nielsen of security researchers.

The Chinese apps have insecure HTTP because the government needs back-doors. I know first hand.
Score: 9 Votes (Like | Disagree)
Puppuccino Avatar
75 months ago
I’ve never downloaded TikTok, I’m not touching that app. Goodness knows what tracking it’s doing.
Score: 8 Votes (Like | Disagree)
phenste Avatar
75 months ago
Oops.
Having seen Vine come and go in what felt like an instant (while I was in high school), the fact that TikTok isn’t dead yet is a MARVEL to me. Especially with how clearly unsafe it is, and how clearly stupid all the teenage influencers on it are.

Vine was the genesis of Jake/Logan Paul, and the most we got out of that was a horribly-poor-taste YouTube video with a hanged corpse in the icon, and Post Malone’s house getting accidentally doxxed. (Yes, Jake Paul is stupid enough to accidentally dox someone.)

With TikTok, I feel like we could get the Chinese government somehow getting into the accounts of EVERY influencer, and every person that follows these influencers, and just…****ing something up majorly. I don’t know what, but if there’s anything I’ve learned in the last few months, it’s that you never know what’s around the corner.
Score: 6 Votes (Like | Disagree)
lkrupp Avatar
75 months ago

Here's the real problem. I recently submitted an app and when you want to opt-out, you have to give a very good reason. Privacy-first Apple should have ended backwards-compatibility years ago. For any serious developer, there is no good reason not to use HTTPS, simple SSL certificates (which are fine for encryption) have always been cheap and now they're even free with Let's Encrypt.
There’s no good reason not to use HTTPS just like there’s no good reason to use Flash... but developers and users DO continue to use them and scream bloody murder when things no longer work. macOS still supports Flash even though it’s a pos. And when something doesn’t work on their Apple gear it’s automatically Apple’s fault no matter what. Just look at all the rage at the 32/64 bit change and APFS. If Apple were to stop supporting HTTP many websites would go dead on the platform. It’s a catch-22.
Score: 4 Votes (Like | Disagree)
mi7chy Avatar
75 months ago
Intercept crappy videos with even crappier ones?
Score: 3 Votes (Like | Disagree)
AlexGraphicD Avatar
75 months ago
LMAO How can people be so clueless and download these kind of spyware in the first place? How can a Chinese social media app become so popular out of the confined borders of that communist regime in this day and age is beyond ridiculous.
Score: 3 Votes (Like | Disagree)