TikTok caught secretly spying on millions of iPhone users
Apple iOS apps can read the last thing copied to clipboard

Apple recently fixed a bug in iOS 14 that allows apps to secretly access the clipboard on Apple devices. The new OS will warn users when an app reads the last item copied to the clipboard, but several apps have already been caught invading people’s privacy, including TikTok, according to security researchers Talal Haj Bakry and Tommy Mysk.
China’s Bytedance, owner of TikTok, stated the problem is tied to an outdated advertising SDK. However, according to the clipboard warning in iOS 14 beta, TikTok is continuing to abuse users’ privacy.
A company spokesperson said it was “triggered by a feature designed to identify repetitive, spammy behavior.” TikTok submitted an updated version of the app without the anti-spam feature to the App Store.
The TikTok spokesperson added: “The clipboard access issues showed up due to third-party SDKs, in our case an older version Google Ads SDK, so we do not get access to the information through this. We are in the processes of updating so that the third-party SDK will no longer have access.”
Changes to Apple’s iOS 14 security and privacy settings helped to identify TikTok and other apps secretly accessing the clipboard. The vulnerability meant anything copied on a user’s Mac or iPad could be read by active apps on their iPhone, including passwords, work documents, personal emails and financial documents.
Apple’s iOS fix will force TikTok and other companies to update their apps.
Apple initially ignored the clipboard vulnerability, eventually publishing a fix following media coverage of the security findings. According to Bakry and Mysk, “Apple dismissed the risks that we highlighted and explained that iOS already had mechanisms to counter all of the risks. But the mechanisms that Apple provided were not effective to protect user privacy.”
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
iPhone users should update their TikTok app when the newest version is released.
David Gargaro has been providing content writing and copy editing services for more than 20 years. He has worked with companies across numerous industries, including (but not limited to) advertising, publishing, marketing, real estate, finance, insurance, law, automotive, construction, human resources, restoration services, and manufacturing. He has also managed a team of freelancers as the managing editor of a small publishing company.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
UK businesses patchy at complying with data privacy rules
News Companies need clear and well-defined data privacy strategies
By Emma Woollacott Published
-
Data privacy professionals are severely underfunded – and it’s only going to get worse
News European data privacy professionals say they're short of cash, short of skilled staff, and stressed
By Emma Woollacott Published
-
Four years on, how's UK GDPR holding up?
News While some SMBs are struggling, most have stepped up to the mark in terms of data governance policies
By Emma Woollacott Published
-
Multicloud data protection and recovery
whitepaper Data is the lifeblood of every modern business, but what happens when your data is gone?
By ITPro Published
-
Intelligent data security and management
whitepaper What will you do when ransomware hits you?
By ITPro Published
-
How to extend zero trust to your cloud workloads
Whitepaper Implement zero trust-based security across your entire ecosystem
By ITPro Published
-
The threat prevention buyer's guide
Whitepaper Find the best advanced and file-based threat protection solution for you
By ITPro Published
-
Why The Matrix offers valuable lessons on data sovereignty for channel partners
Industry Insight Two decades on, there's much that the Matrix series can teach channel partners about data sovereignty
By David Devine Published