4 Sources
[1]
AI and ID verification apps leaked data on millions of Android users
There are millions of apps in the Google Play Store, but not all of them are safe to use. Security researchers have recently identified several apps that contain serious security vulnerabilities. The first app in question According to a Forbes contributor, a seemingly harmless app called Video AI
[2]
AI Image App Leaks 1.5 Million User-Generated Photos
An Android app that promised AI-powered photo and video makeovers instead left a large volume of user content publicly exposed, according to researchers from Cybernews. An app called Video AI Art Generator & Maker, which has been downloaded more than 500,000 times from the Google Play Store,
[3]
Top Android AI photo and video editor exposes nearly two million user images and videos
Misconfigured database holding millions of images and videos found online * Cybernews found misconfigured database in "Video AI Art Generator & Maker" app * Leak exposed 8.27m media files, including 2m private user photos and videos * Developers secured database after disclosure; similar flaws
[4]
Unsecured AI apps are leaking personal data of Android users
AI apps are a "treasure trove" of leaked data, researchers say. Credit: Anadolu Agency / Contributor / Anadolu via Getty Images Not every AI tool you stumble across in your phone's app marketplace is the same. In fact, many of them may be more of a privacy gamble than you would have previously
Share
Copy Link
A popular Android AI app exposed over 12 terabytes of user data, including 1.5 million images and 385,000 videos, through a misconfigured Google Cloud Storage bucket. Cybersecurity researchers warn that 72 percent of AI apps analyzed show similar security vulnerabilities, raising concerns about how these rapidly deployed tools handle user privacy.
A significant data leak affecting Android users has revealed how unsecured AI applications are putting millions at risk. Video AI Art Generator & Maker, an Android app downloaded more than 500,000 times from the Google Play Store, exposed over 12 terabytes of user content through a misconfigured Google Cloud Storage bucket that required no authentication
1
2
. The exposed storage contained more than 1.5 million user-uploaded images and over 385,000 user-uploaded videos, alongside approximately 2.87 million AI-generated images, 2.87 million AI-generated videos, and over 386,000 AI-generated audio files2
. In total, the bucket stored about 8.27 million media files, with 2 million of those being private user-generated photos and videos3
.
Source: PCWorld
Cybernews researchers discovered the backend misconfiguration allowed anyone who knew where to look to access the stored files without authentication
3
. The app, which offered cinematic-style AI makeovers for photos and videos, launched in mid-June 2023, and the storage bucket appeared to contain every file uploaded since the app's launch2
. The database was linked to Codeway Dijital Hizmetler Anonim Sirketi, a private company registered in Turkey2
3
. Google responded quickly to user complaints and removed the app from the Google Play Store after the vulnerability was disclosed1
.
Source: PetaPixel
This isn't an isolated incident for Codeway. Another app associated with the company, Chat & Ask AI, had previously been found to expose a large volume of user messages due to a separate backend misconfiguration
2
. In early February 2026, an independent researcher discovered that this app exposed 300 million messages tied to 25 million users3
. Beyond Codeway's applications, another app called IDMerit exposed know-your-customer data and personally identifiable information from users across 25 countries, predominantly in the U.S., including full names and addresses, birthdates, IDs, and contact information constituting a full terabyte of data4
.
Source: Mashable
Related Stories
Cybersecurity experts warn that lax security trends among AI apps pose a widespread risk to user privacy. Researchers found that roughly 72 percent of the hundreds of Google Play apps analyzed showed similar security vulnerabilities
2
4
. Many AI apps store sensitive user uploads alongside AI-generated content and often use a highly criticized practice known as hardcoding secrets, embedding sensitive information such as API keys, passwords, or encryption keys directly into the app's source code4
. According to Cybernews researchers, "This data leak shows how some AI apps prioritize fast product delivery, skipping crucial security features, such as enabling authentication for the critical cloud storage bucket used to store user data, including images and videos"2
3
. After Cybernews contacted the developers behind Video AI Art Generator & Maker, they secured the exposed database shortly afterward2
. The incident wasn't malicious but due to a configuration error in Google Cloud that allowed anyone to access the stored data without having to identify themselves first1
. For Android users relying on these tools, the leaked personal data represents a significant privacy disaster, particularly as the rush to deploy AI-powered features appears to be outpacing basic security protocols across the rapidly growing AI app ecosystem.Summarized by
Navi
[2]
[3]
20 Jan 2026•Technology

16 Jul 2025•Technology

27 Jan 2026•Technology

1
Science and Research

2
Technology
3
Technology