If you’re using a password-manager (like we’re supposed to!) and use it to copy passwords (say, your Amazon employee internal credentials...) while you have TikTok open, the TikTok app would see it and could upload it somewhere.
...and we only know about this issue now because iOS 14 adds clipboard snooping notifications - and that was only a month ago! Think about the stuff that the app could be doing that we don’t yet know about.
There’s too many bloody-obvious security vulnerabilities that are decades old but don’t get fixed until they either become a meme (like SQL Injection) or the platform vendor does something about it (iOS 14 clipboard notifications) - and don’t forget that the SIGINT community is sitting on millions of dollars worth of zero-days that they won’t disclose to vendors unless they feel like it - so I fully expect there to be more surprises in TikTok - and other apps - in the years to come - probably indefinitely.