TikTok Seller BE cross-origin DOM-read PoC

One click opens the authenticated Seller verification page, activates its heatmap editor from this unrelated origin, connects an attacker-controlled MessagePort, and displays every DOM item the heatmap discloses.

This version intentionally displays captured Seller-page text to demonstrate confidentiality impact. Use only your owned account. Nothing is sent to an external server or saved in browser storage; reloading this page clears the captured data.

Target: https://seller-be.tiktok.com/setup?shop_region=BE. Allow the popup. The PoC performs a bounded scroll scan through the exposed heatmap RPC and returns the popup to the top. It captures only data the heatmap supplies—principally visible element text, paths, and positions—not cookies, storage, input values, or the complete HTML DOM.

If editorLoaded stays false, confirm the popup remains signed in on the exact seller-be.tiktok.com/setup page. Temporarily allow Seller analytics resources from sf16-website-login.neutral.ttwstatic.com and lf-global-static.iapplogcdn.com in any content blocker or DNS filter.

Exploit status

Idle.

Captured DOM details — local display only

#Rendered textContentElement pathPositions / other fields
No DOM items captured.
All captured heatmap items as JSON
[]