Security Researchers Take Advantage of Insecure HTTP to Display Fake Videos on TikTok

An investigation by Talal Haj Bakry and Tommy Mysk has revealed that backwards-compatible support for HTTP in iOS and Android is allowing data from popular apps such as TikTok to be intercepted and altered.

tiktok logo
While most apps have made the transition to HTTPS, the research discovered that TikTok on iOS and Android still uses unencrypted HTTP to download media content. Consequently, TikTok inherits all of the known and well-documented HTTP vulnerabilities.

Apple introduced App Transport Security in iOS 9, requiring all HTTP connections to use encrypted HTTPS. Google similarly changed the default network security configuration in Android Pie to block all plaintext HTTP traffic. HTTP vulnerabilities still exist, however, since Apple and Google continue provide a way for developers to opt-out of HTTPS for backwards-compatibility.


The investigation proved that it is possible to successfully intercept TikTok traffic and fool the app to show fake videos as if they were published by popular and verified accounts. Any router between the TikTok app and TikTok's servers can easily expose a user's watch history, and change profile photos and videos. While only users connected to the router will see the malicious content, the research suggests that if a popular DNS server was hacked to include a corrupt DNS record, media data could be changed on a large scale.

Popular Stories

Apple Logo Spotlight

Report: Apple to Launch These New Products in 2026

Sunday November 2, 2025 5:34 am PST by
Apple is planning to launch at least 15 new products in 2026, according to Bloomberg's Mark Gurman. Gurman outlined what to expect from Apple in 2026 in the latest edition of his "Power On" newsletter. He said the company is heading "into one of its most pivotal years in recent memory," with the rollout of major new Apple Intelligence features, intense regulatory pressure on the App Store,...
ios 26 1 slide to stop

iOS 26.1 Brings Back 2007 Feature in New Way

Friday October 31, 2025 1:40 pm PDT by
The upcoming iOS 26.1 update includes a small but helpful change for iPhones, and it could prevent you from running late to something important. Specifically, when an alarm goes off in the Clock app, there is a new "slide to stop" control on the screen for turning off the alarm. On previous iOS 26 versions, there is simply a large "stop" button, which could be accidentally tapped. The new ...
Apple Intelligence General Feature 2

New Version of Siri to 'Lean' on Google Gemini

Sunday November 2, 2025 6:06 am PST by
In his "Power On" newsletter, Bloomberg's Mark Gurman today provided an update on the status of Apple Intelligence and the plans for it in 2026. Apple is still planning to roll out its revamped version of Siri around March of next year. The release should be accompanied by the release of a new smart home display product with speaker-base and wall-mount options. A new Apple TV and HomePod...
HomePod mini and Apple TV

New Apple TV and HomePod Mini Likely Launching Soon

Sunday November 2, 2025 5:49 am PST by
A new Apple TV and HomePod mini could launch as soon as this month, Bloomberg's Mark Gurman today suggested. In today's "Power On" newsletter, Gurman said that Apple retail stores are planning an overnight refresh on the evening of November 11, where changes will be made after closing, such as refreshing displays and placing new products for the following day. The timing of the overnight...
Apple Foldable Thumb

iPhone Fold: Launch, Pricing, and What to Expect From Apple's Foldable

Friday October 31, 2025 8:52 am PDT by
Apple is expected to launch a new foldable iPhone next year, based on multiple rumors and credible sources. The long-awaited device has been rumored for years now, but signs increasingly suggest that 2026 could indeed be the year that Apple releases its first foldable device. Below, we've collated an updated set of key details that have been leaked about Apple's foldable iPhone so far. Ove...
M5 MacBook Pro

Waiting for New Macs? Apple Just Shared Bad News

Friday October 31, 2025 7:32 am PDT by
Apple has just given a strong indication that it will not be releasing any additional new Macs for the remainder of the year. Apple's CFO Kevan Parekh dropped the hint during the company's earnings call on Thursday:On Mac, keep in mind, we expect to face a very difficult compare against the M4 MacBook Pro, Mac mini, and iMac launches in the year-ago quarter.Parekh essentially gave a heads up ...
iOS 26

Apple Releases iOS 26.1 With Liquid Glass Toggle, Slide to Stop Alarm, New Apple Intelligence Languages and More

Monday November 3, 2025 1:11 pm PST by
Apple today released iOS 26.1, the first major update to the iOS 26 operating system that came out in September, iOS 26.1 comes over a month after iOS 26 launched. ‌iOS 26‌.1 is compatible with the ‌iPhone‌ 11 series and later, as well as the second-generation ‌iPhone‌ SE. The new software can be downloaded on eligible iPhones over-the-air by going to Settings > General >...
iOS 26

6 New Things Your iPhone Can Do in iOS 26.1

Wednesday October 29, 2025 4:22 am PDT by
Apple is about to drop iOS 26.1, the first major point release since iOS 26 was rolled out in September, and there are at least six notable changes and improvements to look forward to. We've rounded them up below. Apple has already provided developers and public beta testers with the release candidate version of iOS 26.1, which means Apple will likely roll out the update to all compatible...
Early Black Friday Deals 2

The Best Early Black Friday Apple Deals

Sunday November 2, 2025 10:04 am PST by
We're officially in the month of Black Friday, which will take place on Friday, November 28 in 2025. As always, this will be the best time of the year to shop for great deals, including popular Apple products like AirPods, iPad, Apple Watch, and more. In this article, the majority of the discounts will be found on Amazon. Note: MacRumors is an affiliate partner with some of these vendors. When ...

Top Rated Comments

patent10021 Avatar
72 months ago
The Leslie Nielsen of security researchers.

The Chinese apps have insecure HTTP because the government needs back-doors. I know first hand.
Score: 9 Votes (Like | Disagree)
Puppuccino Avatar
72 months ago
I’ve never downloaded TikTok, I’m not touching that app. Goodness knows what tracking it’s doing.
Score: 8 Votes (Like | Disagree)
phenste Avatar
72 months ago
Oops.
Having seen Vine come and go in what felt like an instant (while I was in high school), the fact that TikTok isn’t dead yet is a MARVEL to me. Especially with how clearly unsafe it is, and how clearly stupid all the teenage influencers on it are.

Vine was the genesis of Jake/Logan Paul, and the most we got out of that was a horribly-poor-taste YouTube video with a hanged corpse in the icon, and Post Malone’s house getting accidentally doxxed. (Yes, Jake Paul is stupid enough to accidentally dox someone.)

With TikTok, I feel like we could get the Chinese government somehow getting into the accounts of EVERY influencer, and every person that follows these influencers, and just…****ing something up majorly. I don’t know what, but if there’s anything I’ve learned in the last few months, it’s that you never know what’s around the corner.
Score: 6 Votes (Like | Disagree)
lkrupp Avatar
72 months ago

Here's the real problem. I recently submitted an app and when you want to opt-out, you have to give a very good reason. Privacy-first Apple should have ended backwards-compatibility years ago. For any serious developer, there is no good reason not to use HTTPS, simple SSL certificates (which are fine for encryption) have always been cheap and now they're even free with Let's Encrypt.
There’s no good reason not to use HTTPS just like there’s no good reason to use Flash... but developers and users DO continue to use them and scream bloody murder when things no longer work. macOS still supports Flash even though it’s a pos. And when something doesn’t work on their Apple gear it’s automatically Apple’s fault no matter what. Just look at all the rage at the 32/64 bit change and APFS. If Apple were to stop supporting HTTP many websites would go dead on the platform. It’s a catch-22.
Score: 4 Votes (Like | Disagree)
mi7chy Avatar
72 months ago
Intercept crappy videos with even crappier ones?
Score: 3 Votes (Like | Disagree)
AlexGraphicD Avatar
72 months ago
LMAO How can people be so clueless and download these kind of spyware in the first place? How can a Chinese social media app become so popular out of the confined borders of that communist regime in this day and age is beyond ridiculous.
Score: 3 Votes (Like | Disagree)