Over 70% AndreAi has a key leak, over 730 TB files and big user data exposure.

Over 70% AndreAi has a key leak, over 730 TB files and big user data exposure.

A large-scale security survey analysed 1.8 million Android applications in Google Applied Stores, focusing on those that explicitly promote AI functionality. From the initial study sample, Cybernews researchers identified 38630 AndreAi applications and detected data-processing omissions that were far beyond those of independent developers by examining the exposure vouchers and cloud service references in the internal code.

Researchers found that 72 per cent of the analysed Andrea AI applications were directly embedded with at least one hard-coded key in their application code, with an average of 5.1 keys leaked per affected application. Throughout the data collection, researchers agreed to exclude 197092 independent keys, indicating that unsafe coding practices, despite long warnings, remain widespread. More than 81 per cent of the keys detected are linked to Google Cloud infrastructure, including project identifiers, API keys, Firebase databases and storage drums. Among the hard-coded Google Cloud Endpoints detected, there were 26424 consensus points, about two thirds of which pointed to resources that no longer existed. Of the remaining end-points, there are still 8545 Google Cloud storage drums in existence and in need of authentication, while hundreds of them are not properly configured and are publicly accessible, potentially exposing more than 200 million documents to a total of nearly 730 TB user data.

The study also found that 285 Firebase databases, which are completely without identification control, disclosed at least 1.1 GB user data. In 42 per cent of the exposure databases, researchers found data tables marked “conceptual validation”, indicating that they had previously been invaded by assailants. Other databases contain administrator accounts created using an attacker-style e-mail address, proving that the use of the loophole is not a theoretical risk, but a time to proceed. Even after the clear signs of invasion, many of these databases remain unprotected, indicating that the problem is one of poor surveillance rather than one-off errors. Although the focus is on AI functions, leaking large-language models of API keys are relatively rare – only a small number of keyes related to key providers such as OpenAI, Google Gemini and Claude have been detected throughout the data set. In a typical configuration, these leaks only allow the attackers to submit new requests without access to stored conversations, historical tips or previous responses.

Some of the most significant exposures relate to the implementation of payment infrastructure, including a Stripe key that allows for full control of payment systems. Other leaked documents allow access to communication, analysis and customer data platforms, allowing the attackers to impersonate the application or perform unauthorized data extraction.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply