VYPR
High severity8.8NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026

CVE-2022-28799

CVE-2022-28799

Description

The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover with one click.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • TikTok/TikTok applicationdescription
  • TikTok/TikTokllm-fuzzy
    Range: <23.7.3

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.