6.8% of 1,049 AI-Built Apps Found Leaking Private Data Due to Disabled Security Setting
A security researcher scanned 1,049 publicly listed AI-built applications in 2026 and found that 71 of them, roughly 6.8%, had at least one database table containing real private data accessible without any login. The vulnerability stemmed from a known misconfiguration: Row Level Security left disabled on Supabase-backed apps that expose a public API key in the browser's JavaScript. Exposed data included account profiles, private messages, paid usage history, and in one case a master database key granting full read, write, and delete access. The researcher manually reviewed results to exclude 40 apps with intentionally public tables, such as leaderboards and blog posts, before notifying all 71 affected companies individually with details of the exposure and a free offer to help fix it. The findings align with earlier reports from Wiz, Forbes, and The Verge, which have consistently placed the misconfiguration rate among AI-built apps at between one in ten and one in fifteen.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in