【Watch Project X Online】
You know how some popular apps don't let you out of the app when you click on Watch Project X Onlinea link, opening said link in their own little in-app browser instead?
As it turns out, this enables these apps to monitor what you do. And among the most popular apps that do this, TikTok appears to be the worst offender.
In a blog post Thursday, security researcher Felix Krause announced the launch of InAppBrowser, a tool that lists all the JavaScript commands executed by an iOS app as its in-app browser renders a webpage.
You May Also Like
To show what the tool can do, Krause analyzed some popular iOS apps that have an in-app browser, and the results are disturbing. Krause's data shows that apps including TikTok, Instagram, Facebook Messenger, and Facebook, all modify webpages that are opened in the in-app browser. "This includes adding tracking code (like inputs, text selections, taps, etc.), injecting external JavaScript files, as well as creating new HTML elements," Krause says. They also fetch website metadata, though Krause says this is "harmless."
SEE ALSO: TikTok is a growing source of news among UK adultsWhen Krause dug a little deeper into what these apps' in-app browsers really do, he'd found that TikTok does some bad things, including monitoring all of users' keyboard inputs and taps. So, if you open a web page inside of TikTok's app, and enter your credit card details there, TikTok can access all of those details. TikTok is also the only app, out of all the apps Krause has looked into, that doesn't even offer an option to open the link in the device's default browser, forcing you to go through its own in-app browser.
UPDATE: Aug. 23, 2022, 9:59 a.m. EDT In a chat with Motherboard, Krause explained that his report "doesn’t say TikTok is actually recording and using this data." TikTok told the outlet that his findings are "incorrect and misleading.""We do not collect keystroke or text inputs through this code, which is solely used for debugging, troubleshooting, and performance monitoring,” a TikTok spokesperson said.
Check out Motherboard's article.
In a statement to Forbes, a TikTok spokesperson confirmed the practice, but says that "the Javascript code in question is used only for debugging, troubleshooting, and performance monitoring of that experience."
Related Stories
- Can TikTok tell when you've had your heart broken?
- TikTok confirms it censored content critical of China
- The best products that have gone viral on TikTok
- TikTok fined $5.7 million for collecting children's data
It's all needed to provide "an optimal user experience," she said.
Other apps Krause has looked at, like Instagram, also do some monitoring of their own, though none of them go as far as TikTok. And Snapchat and Robinhood are good examples, as they don't modify webpages or fetch their metadata of the sites you open in their in-app browsers.
Krause warns that apps actually have a way of hiding their JavaScript activity from his InAppBrowser tool, meaning they could be doing more monitoring behind the scenes. For now, the only way to make sure they can't do any monitoring is to open websites in the device's default browser — if the app even offers this option.
Topics TikTok
Search
Categories
Latest Posts
The cicadas aren't invading the U.S.
2025-06-26 07:36New discovery reveals the T. Rex was actually super into foreplay
2025-06-26 07:23Here's how women are represented (or not) in LinkedIn's highest
2025-06-26 06:30Your Pornhub habits just got even more private
2025-06-26 06:24The fat bears are already extremely fat
2025-06-26 06:22Popular Posts
Put Me In, Coach!
2025-06-26 07:00Women deserve more credit. For proof, just look at #ThanksForTyping.
2025-06-26 06:16The best Chandler Bing one
2025-06-26 06:00Sexism is the new clickbait. Find another route to internet fame.
2025-06-26 05:39Best vacuum mop combo deal: Save $140 on the Tineco Floor One S5
2025-06-26 04:55Featured Posts
Waitin’ on the Student Debt Jubilee
2025-06-26 07:30Sexism is the new clickbait. Find another route to internet fame.
2025-06-26 07:20Is 'Buffy the Vampire Slayer' getting a revival?
2025-06-26 07:01Best keyboard deals: Save on Asus gaming keyboards at Amazon
2025-06-26 05:38Popular Articles
Whale Vomit Episode 5: Startup Monarchy
2025-06-26 07:36Mary J. Blige and Kanye West drop empowering new anthem
2025-06-26 07:34Here's the deal with those colorful status updates on Facebook
2025-06-26 06:06Your 'wrong person' texts may be linked to Myanmar warlord
2025-06-26 05:15Newsletter
Subscribe to our newsletter for the latest updates.
Comments (935)
Image Information Network
A Typical Wall Street Republican
2025-06-26 07:23Sky Information Network
NASA's Peggy Whitson broke another space record and would she just adopt me already?
2025-06-26 07:20Exploration Information Network
Here's how women are represented (or not) in LinkedIn's highest
2025-06-26 06:59Dynamic Information Network
New discovery reveals the T. Rex was actually super into foreplay
2025-06-26 06:40Quality Information Network
NYT Connections Sports Edition hints and answers for May 19: Tips to solve Connections #238
2025-06-26 05:50