Widely used Android AI photo identification apps have exposed sensitive user data, which has already been obtained by threat actors, according to Cybernews.Apps "Insect Identifier by Photo Cam", "Dog Breed Identifier Photo Cam", and "Spider Identifier App by Photo", which have been downloaded two million times combined, were impacted by a Firebase misconfiguration stemming from inadequate authentication and access controls that leaked over 150,000 users' email addresses, profile photos, usernames, notification tokens, and GPS coordinates, reported Cybernews researchers. While no passwords were found, location data is particularly dangerous as it can reveal where people live or how they move. This information could be abused for stalking, targeted scams, or doxxing, especially when combined with data from earlier breaches.Researchers also found signs that automated bots had already discovered the exposed databases before the investigation. The apps were published under MobilMinds, linked to OZI Technologies, but developers did not respond to repeated requests for comment.
Data Security, Application security, AI/ML

Users’ personal data leaked by popular AI photo apps

(Adobe Stock)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



