These highly-rated apps are leaking user data!
Security firm CovertLabs has discovered that nearly 200 apps on the Apple App Store are leaking data from millions of users. In a post on X, CovertLabs described the situation as "the worst possible."
There's a common thread among the affected apps – most of the top-performing apps are focused on artificial intelligence (AI) . This is particularly concerning, as people often provide AI apps with a significant amount of personal information – for example, questions about mental health, relationships, or finances. In some cases, this personal information is linked to email addresses and phone numbers, and is accessible to anyone.
Which applications are affected?
CovertLabs has created a database of affected applications called Firehound. It ranks applications by the number of exposed files and allows you to view edited samples of the types of leaked files. Below are the most severely compromised applications:
- Codeway's Chat & Ask AI - 406 million copies
- GenZArt - 18 million copies
- YPT - Study Group - 13 million copies
- Adult Coloring Book - Pigment - 7 million copies
- Kmstry - 7 million copies
These five apps alone represent over 20 million users. Chat & Ask AI has a 4.8-star rating with 318,000 reviews on the App Store. Unfortunately, this is no small matter.
Causes of data leaks
The cause of the leak remains unclear. With many of these apps focusing on artificial intelligence (AI), it's possible that developers skipped safety checks in the rush to bring AI tools to market. It's also not entirely clear how these apps managed to bypass Apple's rigorous review process. However, we shouldn't criticize Apple too harshly – privacy issues also exist on Android.
There appears to be no indication that these leaks were intentional or malicious, or that the applications were sending data to third parties – it's simply that users' personal data was exposed in a place easily accessible to bad actors. According to a post from a CovertLabs researcher, data from the application causing the most serious problem, Codeway's Chat & Ask AI, simply sat there, "completely accessible to anyone who knows how to search."
What should you do if you are affected?
Stop using these apps immediately!
CovertLabs has offered to help app developers address these issues – in fact, the Chat & Ask AI app mentioned above has already been fixed. In the meantime, if you are using any of the apps on the list, you should stop immediately. If possible, delete your data from the app and remove it from your personal device.
There appears to be no indication that this data has fallen into the wrong hands, but it's always a possibility, so keep an eye on your account. And if you're particularly concerned about privacy, consider taking extra precautions, such as installing security and privacy extensions for Chrome or adjusting settings on your phone.