TikTok disclosed on HackerOne: IDOR for changing privacy settings...

An Insecure Direct Object Reference (IDOR) vulnerability was found within TikTok Now on Android, which would have allowed any user to change the "Who Can View" privacy setting for another users' Memory. We thank @mrhavit for reporting this to the team.