Microsoft finds TikTok vulnerability that allowed one-click account compromises
Briefly

Deeplinks must be declared in an app's manifest for use outside of the app so, for example, someone who clicks on a TikTok link in a browser has the content automatically opened in the TikTok app.
...
Normally, the TikTok app will allow content from tiktok.com to be loaded into its WebView component but forbid WebView from loading content from other domains.
Read at Ars Technica
[
add
]
[
|
|
]