Moneycontrol PRO
Swing Trading 101
Swing Trading 101

These dangerous AI apps exposed millions of Android users: All the details

Two AI-powered apps listed on the Google Play Store have reportedly exposed millions of personal files, including photos, videos and sensitive identity documents, after a misconfigured cloud storage bucket left user data publicly accessible.

February 23, 2026 / 09:21 IST
Smartphones
Snapshot AI
  • Over 12TB of user data exposed by popular AI apps on Play Store
  • IDMerit app KYC data leak impacts users in 25+ countries
  • Researchers urge caution with AI and identity verification apps

Security researchers have uncovered a major data exposure linked to apps distributed via the Google Play Store, raising fresh concerns about the risks posed by unvetted AI tools.

One app at the centre of the controversy, Video AI Art Generator & Maker, has been installed more than 500,000 times and amassed over 11,000 reviews. According to a report cited by Forbes, the app leaked more than 1.5 million user images, over 385,000 videos and millions of AI-generated files.

Researchers found that a misconfigured Google Cloud Storage bucket allowed unauthenticated access to stored media. In total, more than 12TB of data — representing 8.27 million files accumulated since the app’s launch on June 13, 2023 — was reportedly exposed.

The app no longer appears publicly searchable on the Play Store following disclosure of the issue.

KYC data also exposed

The situation worsens with a second app from the same developer, IDMerit, which reportedly exposed Know Your Customer, or KYC, data. KYC information includes identity documents, addresses, phone numbers and other personally identifiable details required by financial institutions to verify customers.

The exposed data allegedly affected users in the United States and at least 25 other countries, including Germany, France, China and Brazil. Reports described the leak as a “treasure trove” of personal information.

The developer behind both apps, Codeway, has since secured access to the affected IDMerit data as of February 3, according to researchers. However, the scale of the exposure highlights systemic weaknesses in app security practices.

The hardcoding problem

Much of the risk stems from a widely criticised development practice known as hardcoding secrets. This involves embedding sensitive credentials such as passwords or encryption keys directly into an app’s source code. If exposed, these keys can be harvested by automated bots scanning public repositories such as GitHub — sometimes within seconds.

Cybernews researchers found that 72 per cent of the Play Store apps they analysed contained similar vulnerabilities.

How to reduce your risk

Users should exercise caution before installing AI editing or identity verification apps, particularly lesser-known ones. Checking a developer’s portfolio can offer clues. A large number of near-identical apps may suggest a volume-driven approach rather than a security-focused one.

It is also advisable to look for Google’s “Verified Developer” badge on the Play Store, review app permissions carefully and avoid uploading sensitive identity documents unless absolutely necessary.

 

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Sarthak Singh Sarthak is an experienced writer having covered personal and consumer tech, gadgets news, social media trends, and more for several years
first published: Feb 23, 2026 09:21 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347