Chat & Ask AI app exposed 300 million chatbot messages
A misconfigured Firebase backend behind Chat & Ask AI, a popular app fronting ChatGPT, Claude and Gemini, exposed around 300 million messages from more than 25 million users, including full conversation histories. The developer fixed it within hours of the researcher's report.
- Disclosed
- 5 Feb 2026
- Organization
- Codeway
- Vendor
- Multiple models
- Product
- Chat & Ask AI
- Kind of AI
- Chatbot
- AI's role
- AI was the target
- How it happened
- Leaky AI product: Exposed datastore
- Harm
- Data exposed
- Data involved
- Chat logs, Personal data
- Reach
- One organization
- Records
- 25,000,000
- Severity
- High
- Model at fault
- No
- Status
- Confirmed