A security lab's responsible disclosure kept a billion phones' cameras private

ccerrato147 · x · 2026-09-19

depthfirst discovered a TikTok camera-related vulnerability — found using dfs-large1, their security model post-trained on GLM 5.2 (an MIT-licensed, 753B-parameter open-weights model) — and told TikTok, worked with them, and waited for the patch before publishing any footage. No user's camera was abused.

The author's takeaway: a billion phones stayed private because a funded lab decided to send an email first, pushing back on headlines framing free AI software as a "supercharger for hackers."

Related event: Critical TikTok Flaw Let Attackers Access Camera, Mic and Payment Data(4 posts)→

Original post →

More from Safety

Safety channel →