Drop links below. ⬇️

We know the parent company (ByteDance) runs bounty programs for TikTok. But what about CapCut?

With millions of creators storing drafts & data on ByteDance servers, the attack surface is MASSIVE.

If ByteDance is listening: A clear rewards framework for CapCut would attract top talent before attackers find the low-hanging fruit. 🍍

#BugBounty #InfoSec #EthicalHacking #ByteDance

Before I disclose: Is there a private HackerOne/third-party program, or are we going straight to VDP? 👀

Capcut Bug Bounty [work] -

Drop links below. ⬇️

We know the parent company (ByteDance) runs bounty programs for TikTok. But what about CapCut?

With millions of creators storing drafts & data on ByteDance servers, the attack surface is MASSIVE.

If ByteDance is listening: A clear rewards framework for CapCut would attract top talent before attackers find the low-hanging fruit. 🍍

#BugBounty #InfoSec #EthicalHacking #ByteDance

Before I disclose: Is there a private HackerOne/third-party program, or are we going straight to VDP? 👀