Social media app TikTok has been found to have had a security flaw which could have allowed attackers to extract sensitive data from users’ devices for identity theft attacks, phishing or blackmail.

The vulnerability was discovered by cybersecurity researchers from Imperva and has since been fixed. The researchers found that a malicious message could be sent to the TikTok web application through the PostMessage API, which would bypass any security measures.

The message event handler would then process the message and deem it secure, granting the attacker access to valuable information. Data that could have been obtained by the attacker includes user device data, videos viewed, time spent on each video, user account data, and search queries.

TikTok is already a controversial app, built by Chinese company ByteDance and used by more than 1.5 billion people worldwide, including 150 million in the United States alone. The US government has recently been scrutinizing and banning Chinese companies, alleging that the government in China has a tight grip on them and could force them to allow unauthorized backdoor access at any point. Huawei was banned from developing the 5G infrastructure in the US for that very reason.

The US government has previously forced TikTok to store all data in the country and recently told its employees to remove the app from government-issued devices due to matters of national security. TikTok denies any wrongdoing.

The TikTok vulnerability follows numerous cybersecurity issues associated with social media apps, including Facebook and Twitter. In recent years, social media has become a hotbed for cyber threats, with phishing attacks and identity theft incidents increasing at an alarming rate.

Imperva’s discovery highlights the need for businesses and individuals to be aware of the potential dangers and take steps to protect their data. As social media continues to grow in popularity, cybersecurity risks are likely to increase further, making it even more important for companies to prioritize data protection.