AI App Security Flaws Expose Millions of Android Users’ Data
A growing number of unsecured AI applications on the Google Play Store are leaking sensitive personal data from Android users, including images, videos, and personally identifiable information (PII). Recent investigations reveal vulnerabilities in these apps, raising serious privacy concerns and highlighting the risks associated with rapidly proliferating AI tools.
Data Breaches and Exposed Information
Cybersecurity experts have uncovered that several unlicensed or unsecured AI apps, marketed for tasks like identity verification and photo/video editing, have exposed billions of records. One app, “Video AI Art Generator &. Maker,” leaked over 1.5 million user images, more than 385,000 videos, and millions of AI-generated media files. This breach occurred due to a misconfiguration in a Google Cloud Storage bucket, allowing unauthorized access to the data. In total, over 12 terabytes of user media files were accessible.
Another app from the same developer, IDMerit, exposed “Grasp-Your-Customer” (KYC) data from users in 25 countries, including the U.S., Germany, France, China, and Brazil. This sensitive information included full names, addresses, dates of birth, national IDs, phone numbers, email addresses, and even telco metadata. The exposed data represents a significant risk of identity theft and fraud.
The Role of Hardcoded Secrets
A contributing factor to these vulnerabilities is the practice of “hardcoding secrets” – embedding sensitive information like passwords and encryption keys directly into the app’s source code. Research indicates that 72% of apps analyzed on the Play Store exhibited this vulnerability, making them susceptible to compromise by malicious actors scanning public repositories like GitHub.
Google’s Response and Security Measures
Despite these breaches, Google is actively working to improve the security of the Play Store. In 2025, Google prevented 1.75 million policy-violating apps from being published, a decrease from 2.36 million in 2024 and 2.28 million in 2023. The company also banned over 80,000 developer accounts attempting to publish malicious apps, down from 158,000 in 2024 and 333,000 in 2023.
Google attributes this progress to increased investment in AI-powered security systems and proactive defenses. The company now runs over 10,000 safety checks on each app before and after publication, and has integrated generative AI models into the app review process to identify complex malicious patterns more efficiently. Google plans to further increase its AI investments in 2026.
The developer of IDMerit and Video AI Art Generator & Maker secured access to the IDMerit data on February 3rd, according to researchers.
Protecting Yourself: How to Avoid Risky AI Apps
- Check the Developer’s Portfolio: Be wary of developers with a large number of similar-looking apps, as this may indicate a focus on quantity over quality.
- Look for the “Verified Developer” Badge: Google’s “Verified Developer” badge signifies a level of trust and accountability.
- Monitor App Performance: Pay attention to apps that cause your phone to overheat or drain the battery excessively, even when not in use.
- Be Cautious of Lifetime Subscriptions: Question apps offering lifetime Pro subscriptions at unusually low prices.
- Use Google Play Protect: Regularly scan your device for potential threats using Google’s built-in Play Protect feature (Play Store > Profile icon > Play Protect > Scan).
Looking Ahead
As AI technology continues to evolve, the need for robust security measures and user awareness will become increasingly critical. Google’s ongoing efforts to leverage AI in app security are a positive step, but users must remain vigilant and practice safe app habits to protect their personal data. The ongoing battle between security measures and malicious actors will likely continue, requiring constant adaptation and innovation.