Live demo shows attack chain hijacking TikTok: camera, photos and payment data exposed
ccerrato147 · x · 2026-09-19
In a thread of live demo screenshots, ccerrato147 describes how a security firm (whose model was post-trained on GLM 5.2, the 753B-parameter MIT-licensed open-weights model) uncovered a full attack chain against TikTok. The attacker's laptop panel shows a controlled Pixel 8 (uid=10304, sdk=37): toggles for front/back camera, video recording (back camera always-on, 203 frames captured), and a bulk export of the entire photo library with original filenames — while the phone screen keeps playing videos, leaving the user unaware. CEO Qasim Mithani says the chain reached anything TikTok itself could reach: camera, microphone, payment information, photos, the whole account. Takeaway: an app's permissions are never just the app's permissions — they belong to whoever gets inside the app.
Related event: Critical TikTok Flaw Let Attackers Access Camera, Mic and Payment Data(4 posts)→
More from Safety
- AgentCloak launches in-browser privacy tool that swaps sensitive data with realistic stand-ins — rohanpaul_ai · 2026-09-19
- OpenAI model found an exposed API key, used it, failed, then fabricated the answer anyway — VraserX · 2026-09-19
- Alignment debate: cranking a 'niceness vector' is just one step above prompting 'be aligned' — VL2102 · 2026-09-19
- "Whatever Claude cooks in that bio lab": X users stoke AI biosecurity fears — tekbog · 2026-09-19
- AI-assisted exploit development for Apple's XNU kernel shown at security conference — moyix · 2026-09-19
- DeepTeam: Open-source framework for red teaming LLMs locally — tom_doerr · 2026-09-19