An independent cyber-security researcher has warned that the Chinese short-form video app TikTok may be monitoring all keyboard inputs and taps via its in-app browser on iOS.
According to Felix Krause, Founder of Fastlane, which was acquired by Google, when a user opens any link on the TikTok iOS app, it opens inside their in-app browser.
“While you are interacting with the website, TikTok subscribes to all keyboard inputs (including passwords, credit card information, etc.) and every tap on the screen, like which buttons and links you click,” Krause claimed in a blog post on Thursday.
According to him, TikTok iOS subscribes to every keystroke (text input) that occurs on third-party websites rendered inside the TikTok app.
“This can include passwords, credit card information and other sensitive user data,” Krause added.
This is the technical equivalent of installing a keylogger on third-party websites.
The company confirmed that those features exist in the code but that they are not used on its in-app browser in the iOS app.
According to the researcher, it proves that “TikTok injects code into third party websites through their in-app browsers that behaves like a keylogger. However, claims it’s not being used”.
“This was an active choice the company made. This is a non-trivial engineering task. This does not happen by mistake or randomly,” he mentioned.