Security research lab CovertLabs, in collaboration with some users, is uncovering a number of (mostly) artificial intelligence (AI)-related apps found in the App Store that are exposing user data, including names, emails, and chat history. As spotted by user @vxunderground on X, the Firehound project is scanning the store and creating a list of apps that are exposing and leaking sensitive user data.

The Firehound project was started by OSINT researcher @Harrris0n to search for artificial intelligence-related vulnerabilities in the Apple App Store.
Firehound: Hundreds of dangerous apps
198 iOS apps leak user have been identified that information . As expected, the top apps are all related to artificial intelligence . Of the 198 apps recorded so far, 196 expose user data.
See also: One click is enough: 'Reprompt' turns Microsoft Copilot into a data extraction tool
The “ Chat & Ask AI ” app leads Firehound’s rankings for “ Most files exposed ” and “ Most records exposed ,” with more than 406 million files from over 18 million users exposed. @Harris0n warned users to stop using the app immediately due to a critical vulnerability that exposes the entire chat history. Over 380 million messages are accessible to anyone who knows where to look.
Most of the applications in Firehound appear to be exposing data via improperly secured databases or cloud storage. While most of the applications appear to be related to artificial intelligence, the affected application categories include several types:
- Education
- Entertainment
- Graphics & Design
- Health & Physical Condition
- Lifestyle
- Social Networking
- But

Firehound restricts free access to data
Firehound restricts open access to the data and requires users to register to request limited datasets and detailed scan results. Some scan results are highly sensitive, and until they can be responsibly vetted, they cannot be fully released. The public registry is intentionally limited, and users can request access to limited datasets and views after creating an account.
See also: Cloud marketplace Pax8 accidentally exposes data of 1,800 MSP partners
Access requests are reviewed manually, with priority given to journalists, law enforcement, and security professionals. After logging in, users will be prompted to submit a request from their dashboard.

Despite initial claims that Firehound catalogs “AI Slop,” this information is not directly referenced on @Harrris0n’s profile or Firehound’s website. While many of the apps appear to be AI-related, it is currently impossible to determine with certainty whether they were released as a result of vibe coding or other AI-assisted development tools.
See also: No, Google Gemini won't get data from your iPhone
Still, Firehound serves as a reminder that users need to be careful about the platforms they use and the information they share, especially when it comes to AI chatbots. Developers also need to take responsibility for the security of user data, no matter how low the barrier to entry for developing and launching an app may be.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
