Top photo ID apps leak user data – over 150,000 believed to have been affected


  • Cybernews found three misconfigured photo ID apps leaking sensitive user data via exposed Firebase instances
  • Breach exposed emails, usernames, profile pictures, GPS coordinates, and notification tokens, affecting ~152,000 users
  • Hackers already had access to the open databases; developers do not respond despite repeated contact attempts

Several mobile applications that identified objects in photographs leaked highly sensitive information on the Internet and hackers managed to pick them up.

All three applications had misconfigured Firebase instances, resulting in insufficient authentication and access control. The data resided in an open database and included people’s email addresses, usernames (often including full names), Firebase Cloud Messaging (FCM) notification tokens, profile pictures and GPS coordinates.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top