AI Apps Leak 1.5 Million Images as Security Flaws Expose Millions of Android Users

Reviewed byNidhi Govil

4 Sources

Share

A popular Android AI app exposed over 12 terabytes of user data, including 1.5 million images and 385,000 videos, through a misconfigured Google Cloud Storage bucket. Cybersecurity researchers warn that 72 percent of AI apps analyzed show similar security vulnerabilities, raising concerns about how these rapidly deployed tools handle user privacy.

AI Apps Expose Massive Trove of User Data Through Cloud Misconfiguration

A significant data leak affecting Android users has revealed how unsecured AI applications are putting millions at risk. Video AI Art Generator & Maker, an Android app downloaded more than 500,000 times from the Google Play Store, exposed over 12 terabytes of user content through a misconfigured Google Cloud Storage bucket that required no authentication

1

2

. The exposed storage contained more than 1.5 million user-uploaded images and over 385,000 user-uploaded videos, alongside approximately 2.87 million AI-generated images, 2.87 million AI-generated videos, and over 386,000 AI-generated audio files

2

. In total, the bucket stored about 8.27 million media files, with 2 million of those being private user-generated photos and videos

3

.

Source: PCWorld

Source: PCWorld

Security Vulnerabilities Plague AI App Ecosystem

Cybernews researchers discovered the backend misconfiguration allowed anyone who knew where to look to access the stored files without authentication

3

. The app, which offered cinematic-style AI makeovers for photos and videos, launched in mid-June 2023, and the storage bucket appeared to contain every file uploaded since the app's launch

2

. The database was linked to Codeway Dijital Hizmetler Anonim Sirketi, a private company registered in Turkey

2

3

. Google responded quickly to user complaints and removed the app from the Google Play Store after the vulnerability was disclosed

1

.

Source: PetaPixel

Source: PetaPixel

Pattern of Negligence Across Multiple Applications

This isn't an isolated incident for Codeway. Another app associated with the company, Chat & Ask AI, had previously been found to expose a large volume of user messages due to a separate backend misconfiguration

2

. In early February 2026, an independent researcher discovered that this app exposed 300 million messages tied to 25 million users

3

. Beyond Codeway's applications, another app called IDMerit exposed know-your-customer data and personally identifiable information from users across 25 countries, predominantly in the U.S., including full names and addresses, birthdates, IDs, and contact information constituting a full terabyte of data

4

.

Source: Mashable

Source: Mashable

Widespread Security Concerns Across AI App Marketplace

Cybersecurity experts warn that lax security trends among AI apps pose a widespread risk to user privacy. Researchers found that roughly 72 percent of the hundreds of Google Play apps analyzed showed similar security vulnerabilities

2

4

. Many AI apps store sensitive user uploads alongside AI-generated content and often use a highly criticized practice known as hardcoding secrets, embedding sensitive information such as API keys, passwords, or encryption keys directly into the app's source code

4

. According to Cybernews researchers, "This data leak shows how some AI apps prioritize fast product delivery, skipping crucial security features, such as enabling authentication for the critical cloud storage bucket used to store user data, including images and videos"

2

3

. After Cybernews contacted the developers behind Video AI Art Generator & Maker, they secured the exposed database shortly afterward

2

. The incident wasn't malicious but due to a configuration error in Google Cloud that allowed anyone to access the stored data without having to identify themselves first

1

. For Android users relying on these tools, the leaked personal data represents a significant privacy disaster, particularly as the rush to deploy AI-powered features appears to be outpacing basic security protocols across the rapidly growing AI app ecosystem.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo