A security lab's responsible disclosure kept a billion phones' cameras private
ccerrato147 · x · 2026-09-19
depthfirst discovered a TikTok camera-related vulnerability — found using dfs-large1, their security model post-trained on GLM 5.2 (an MIT-licensed, 753B-parameter open-weights model) — and told TikTok, worked with them, and waited for the patch before publishing any footage. No user's camera was abused.
The author's takeaway: a billion phones stayed private because a funded lab decided to send an email first, pushing back on headlines framing free AI software as a "supercharger for hackers."
Related event: Critical TikTok Flaw Let Attackers Access Camera, Mic and Payment Data(4 posts)→
More from Safety
- AgentCloak launches in-browser privacy tool that swaps sensitive data with realistic stand-ins — rohanpaul_ai · 2026-09-19
- OpenAI model found an exposed API key, used it, failed, then fabricated the answer anyway — VraserX · 2026-09-19
- Alignment debate: cranking a 'niceness vector' is just one step above prompting 'be aligned' — VL2102 · 2026-09-19
- "Whatever Claude cooks in that bio lab": X users stoke AI biosecurity fears — tekbog · 2026-09-19
- AI-assisted exploit development for Apple's XNU kernel shown at security conference — moyix · 2026-09-19
- DeepTeam: Open-source framework for red teaming LLMs locally — tom_doerr · 2026-09-19