A report published September 18, 2026, described a DepthFirst employee remotely accessing a phone’s camera and photo roll while the phone was browsing TikTok. The reported incident involved a security-research demonstration.
How AI supported the research
DepthFirst CEO Qasim Mithani said the company used its platform and dfs-large1 to find the vulnerabilities. He described dfs-large1 as post-trained on GLM 5.2 through reinforcement learning.
What DepthFirst said the vulnerabilities could reach
Mithani said the vulnerabilities could have allowed access to anything on a device that TikTok itself could access. In addition to the camera and photos, he named the microphone, payment information and the user’s TikTok account.
DepthFirst says it worked with TikTok on a patch
Mithani said DepthFirst disclosed the vulnerabilities to TikTok and worked with the company to patch them before public disclosure.