{"id":381147,"date":"2026-01-20T23:09:14","date_gmt":"2026-01-20T23:09:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/381147\/"},"modified":"2026-01-20T23:09:14","modified_gmt":"2026-01-20T23:09:14","slug":"welcome-to-the-ai-slop-security-crisis-these-198-ios-apps-were-found-leaking-private-chats-and-user-locations","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/381147\/","title":{"rendered":"Welcome to the \u2018AI slop\u2019 security crisis \u2013 these 198 iOS apps were found leaking private chats and user locations"},"content":{"rendered":"<p>Security researchers have discovered scores of mobile apps leaking dataPrivate messages of over 20 million people are exposedThe affected apps have been grouped under the Firehound name<\/p>\n<p id=\"29437ae9-2000-47cc-b67f-ee790a4d9f5e\"><a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/tag\/apple\" data-auto-tag-linker=\"true\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/tag\/apple\" rel=\"nofollow noopener\" target=\"_blank\">Apple<\/a> often uses the security of its <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/computing\/websites-apps\/apple-reveals-the-17-must-download-apps-of-2025-the-app-store-award-winners-are-here\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/computing\/websites-apps\/apple-reveals-the-17-must-download-apps-of-2025-the-app-store-award-winners-are-here\" rel=\"nofollow noopener\" target=\"_blank\">App Store<\/a> as a reason why regulators shouldn\u2019t force it to open up its app ecosystem to <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/computing\/software\/heres-what-third-party-iphone-app-stores-will-look-like-and-how-theyll-work\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/computing\/software\/heres-what-third-party-iphone-app-stores-will-look-like-and-how-theyll-work\" rel=\"nofollow noopener\" target=\"_blank\">rival stores<\/a>. After all, the argument goes, Apple vets its App Store for security and ejects apps that are careless with user data. Yet a recent discovery suggests that the App Store isn\u2019t quite as watertight as it seems.<\/p>\n<p>According to malware researchers <a data-analytics-id=\"inline-link\" href=\"https:\/\/x.com\/vxunderground\/status\/2013340897493004389\" target=\"_blank\" data-url=\"https:\/\/x.com\/vxunderground\/status\/2013340897493004389\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow\">VX Underground on X<\/a>, security firm CovertLabs is working on a project to document <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/pro\/security\/thousands-of-ios-apps-found-to-expose-user-data-and-leak-stripe-keys\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/pro\/security\/thousands-of-ios-apps-found-to-expose-user-data-and-leak-stripe-keys\" rel=\"nofollow noopener\" target=\"_blank\">iOS apps that leak user information<\/a> into the wild. At the time of VX Underground\u2019s X post, 198 guilty apps had been identified, with the top culprits all being related to <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/news\/what-is-ai-everything-you-need-to-know\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/news\/what-is-ai-everything-you-need-to-know\" rel=\"nofollow noopener\" target=\"_blank\">artificial intelligence (AI)<\/a> in some way.<\/p>\n<p><a id=\"elk-seasonal\" class=\"paywall\" aria-hidden=\"true\" data-url=\"\" href=\"\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"\/><\/p>\n<p id=\"29437ae9-2000-47cc-b67f-ee790a4d9f5e-2\">The worst offender was an app named Chat &amp; Ask AI by Codeway, which <a data-analytics-id=\"inline-link\" href=\"https:\/\/x.com\/Harrris0n\/status\/2013000392846856456\" target=\"_blank\" data-url=\"https:\/\/x.com\/Harrris0n\/status\/2013000392846856456\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow\">according to CovertLabs<\/a> has exposed the entire chat history of some 18 million users \u2013 that\u2019s a total of 380 million messages \u2013 as well as user phone numbers and email addresses. This information is apparently \u201ccompletely accessible to anyone who knows where to look\u201d which, considering the sensitive information people often feed into AIs, is \u201cas bad as it gets,\u201d CovertLabs says.<\/p>\n<p>You may like<\/p>\n<p>Study app &#8216;YPT \u2013 Study Group&#8217; was also found to be at fault, with research indicating that information from over two million users was exposed. That includes chat messages, AI tokens, user IDs and user keys, according to VX Underground.<\/p>\n<p>CovertLabs has created a repository of affected apps, which it has named <a data-analytics-id=\"inline-link\" href=\"https:\/\/firehound.covertlabs.io\/\" target=\"_blank\" data-url=\"https:\/\/firehound.covertlabs.io\/\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">Firehound<\/a>. You can browse through redacted sample data to see what information was leaked, as well as which apps have been exposed the most. Much of the data is sensitive and has been restricted, with interested parties needing to request access to the information.<\/p>\n<p>CovertLabs says that affected developers should reach out to the firm, at which point the app will be removed from the repository and the developers will receive help on how to fix their apps.<\/p>\n<p><a id=\"elk-273f7bc6-5b01-46c5-83c3-da5860d43c2c\" class=\"paywall\" aria-hidden=\"true\" data-url=\"\" href=\"\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"\/>Bad for users, developers and Apple<\/p>\n<p class=\"vanilla-image-block\" style=\"padding-top:56.19%;\">\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2026\/01\/8eNjPiJTRi72AXggVqB5YN.jpg\" alt=\"app security\"   loading=\"lazy\" data-new-v2-image=\"true\" data-original-mos=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2026\/01\/8eNjPiJTRi72AXggVqB5YN.jpg\" data-pin-media=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2026\/01\/8eNjPiJTRi72AXggVqB5YN.jpg\" class=\"inline\"\/>\n<\/p>\n<p>(Image credit: Shutterstock.com)<\/p>\n<p id=\"321642b8-8071-4035-bf9a-d410518b553c\">The fact that many of the leakiest apps \u2013 including Chat &amp; Ask AI, GenZArt, Kmstry and Genie \u2013 are related to AI isn&#8217;t too surprising. In the rush to capitalize on the AI goldmine, it\u2019s likely that many developers have cut corners or implemented lax security measures in order to get their app out the door and onto the App Store.<\/p>\n<p class=\"newsletter-form__strapline\">Sign up for breaking news, reviews, opinion, top tech deals, and more.<\/p>\n<p>But some of the blame should probably also fall at the feet of Apple. The company takes pride in the <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/pro\/security\/app-stores-are-increasingly-becoming-a-major-security-worry\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/pro\/security\/app-stores-are-increasingly-becoming-a-major-security-worry\" rel=\"nofollow noopener\" target=\"_blank\">security of its App Store<\/a> compared to the likes of the <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/vpn\/vpn-privacy-security\/why-is-there-so-much-spyware-hidden-in-the-play-store\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/vpn\/vpn-privacy-security\/why-is-there-so-much-spyware-hidden-in-the-play-store\" rel=\"nofollow noopener\" target=\"_blank\">Google Play Store<\/a>, which is often found to contain <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/phones\/researcher-compares-android-and-ios-security-and-theres-a-clear-loser\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/phones\/researcher-compares-android-and-ios-security-and-theres-a-clear-loser\" rel=\"nofollow noopener\" target=\"_blank\">more malicious and insecure apps<\/a> than Apple\u2019s effort.<\/p>\n<p>Yet that\u2019s <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/pro\/security\/apple-ios-apps-are-worse-at-leaking-sensitive-data-than-android-apps-finds-worrying-research-heres-what-you-need-to-know\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/pro\/security\/apple-ios-apps-are-worse-at-leaking-sensitive-data-than-android-apps-finds-worrying-research-heres-what-you-need-to-know\" rel=\"nofollow noopener\" target=\"_blank\">not always the case<\/a> \u2013 Apple\u2019s App Store has problems of its own, and the fact that such vulnerable apps have seemingly made it past the App Store\u2019s review process is not a good look for Apple.<\/p>\n<p>If you use any of the affected apps, you should stop immediately. You won\u2019t be able to do much about the data that\u2019s already exposed, but you can at least stop adding more. You should also start using one of the <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/best\/password-manager\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/best\/password-manager\" rel=\"nofollow noopener\" target=\"_blank\">best password managers<\/a> and change the passwords of any accounts that share the email address you used for the compromised apps. If you know anyone else using these apps, warn them about the dangers.<\/p>\n<p>Hopefully, the affected developers will be able to secure their apps \u2013 and other developers will learn about the risks before it\u2019s too late.<\/p>\n<p id=\"f553fe26-8f65-48a9-8916-1020694d1676\"><a data-analytics-id=\"inline-link\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJsWTJoeVlXUmhjaTVqYjIwb0FBUAE?hl=en-GB&amp;gl=GB&amp;ceid=GB%3Aen\" data-url=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJsWTJoeVlXUmhjaTVqYjIwb0FBUAE?hl=en-GB&amp;gl=GB&amp;ceid=GB%3Aen\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">Follow TechRadar on Google News<\/a> and <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.google.com\/preferences\/source?q=techradar.com\" data-url=\"https:\/\/www.google.com\/preferences\/source?q=techradar.com\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">add us as a preferred source<\/a> to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!<\/p>\n<p>And of course you can also <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.tiktok.com\/@techradar\" data-url=\"https:\/\/www.tiktok.com\/@techradar\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">follow TechRadar on TikTok<\/a> for news, reviews, unboxings in video form, and get regular updates from us on <a data-analytics-id=\"inline-link\" href=\"https:\/\/whatsapp.com\/channel\/0029Va6HybZ9RZAY7pIUK12h\" data-url=\"https:\/\/whatsapp.com\/channel\/0029Va6HybZ9RZAY7pIUK12h\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">WhatsApp<\/a> too.<\/p>\n<p><a id=\"elk-203faee5-c342-4bad-a18b-45da06acf458\" class=\"paywall\" aria-hidden=\"true\" data-url=\"\" href=\"\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"\/><\/p>\n<p>Today&#8217;s best NordVPN NordPass deals<\/p>\n<p><a data-google-interstitial=\"false\" aria-label=\"View NordVPN NordPass on NordPass\" href=\"https:\/\/go.nordpass.io\/aff_c?offer_id=645&amp;aff_id=39632&amp;url_id=23213&amp;aff_sub=trd-us-1460475839699322866\" referrerpolicy=\"no-referrer-when-downgrade\" class=\"hawk-affiliate-link-container\" data-product-key=\"72367-1206114998\" data-url=\"https:\/\/go.nordpass.io\/aff_c?offer_id=645&amp;aff_id=39632&amp;url_id=23213&amp;aff_sub=trd-us-1460475839699322866\" data-model-id=\"771323\" data-match-id=\"712244141\" data-product-type=\"2500\" data-link-merchant=\"NordPass\" data-merchant-id=\"151292\" data-merchant-name=\"NordPass\" data-merchant-url=\"https:\/\/nordpass.com\/\" rel=\"sponsored noopener nofollow\" target=\"_blank\" role=\"link\" tabindex=\"0\"><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2026\/01\/uz0mtap1rhib8fho-15871235480434-100-80.png.webp.webp\" alt=\"NordPass\" title=\"NordPass\" class=\"hawk-lazy-image-logo-image\" draggable=\"false\" loading=\"lazy\" width=\"80\" height=\"40\"\/><\/a><br \/>\n<script async src=\"\/\/www.tiktok.com\/embed.js\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Security researchers have discovered scores of mobile apps leaking dataPrivate messages of over 20 million people are exposedThe&hellip;\n","protected":false},"author":2,"featured_media":381148,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":{"0":"post-381147","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-artificialintelligence","11":"tag-technology","12":"tag-uk","13":"tag-united-kingdom","14":"tag-unitedkingdom"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/381147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=381147"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/381147\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/381148"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=381147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=381147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=381147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}