TikTok Bug Bounty
Public bug bounty on HackerOne for the TikTok properties listed in the current program brief.
Tags: vendor, hackerone, mobile
- Program model
- Vendor on HackerOne
- Regions
- Global
- Payout
- Varies by program
Specialties: web, api, mobile
How to approach it
Scope first. Treat the live HackerOne brief as the asset list, not every hostname that resolves under a TikTok domain.
- Separate web, API, and mobile scope before you pick a target.
- Confirm the current policy page before testing.