One click opens the authenticated Seller verification page, activates its heatmap editor from
this unrelated origin, connects an attacker-controlled MessagePort, and displays
every DOM item the heatmap discloses.
This version intentionally displays captured Seller-page text to demonstrate confidentiality impact. Use only your owned account. Nothing is sent to an external server or saved in browser storage; reloading this page clears the captured data.
Target: https://seller-be.tiktok.com/setup?shop_region=BE.
Allow the popup. The PoC performs a bounded scroll scan through the exposed heatmap RPC and
returns the popup to the top. It captures only data the heatmap supplies—principally visible
element text, paths, and positions—not cookies, storage, input values, or the complete HTML DOM.
If editorLoaded stays false, confirm the popup remains signed in on the exact
seller-be.tiktok.com/setup page. Temporarily allow Seller analytics resources from
sf16-website-login.neutral.ttwstatic.com and
lf-global-static.iapplogcdn.com in any content blocker or DNS filter.
Idle.
| # | Rendered textContent | Element path | Positions / other fields |
|---|---|---|---|
| No DOM items captured. | |||
[]