A security researcher discovered a data exposure affecting Chat & Ask AI, one of the most downloaded AI chat applications on the Google Play and Apple App Stores with more than 50 million users. The researcher reported accessing roughly 300 million messages from over 25 million users through a misconfigured Google Firebase backend that left the database open.
According to the disclosure, the exposed conversations included sensitive material, ranging from discussions of illegal activity to requests related to self-harm. Because the messages were tied to individual user records, the exposure raised privacy concerns for a large share of the app's user base.
The incident illustrates a recurring pattern in AI application security, where the underlying data storage rather than the AI model itself becomes the point of failure. A misconfigured cloud database can leave large volumes of user data reachable without authentication, independent of how the AI system processes inputs.
The Chat & Ask AI exposure was among the larger chatbot-related data incidents reported in 2026 by volume of messages involved. Security researchers noted that consumer AI apps often collect and retain extensive conversation histories, which increases the potential impact when a storage layer is left unsecured.
The disclosure followed a broader set of AI-related security events in 2026, including reports of account hijacking through chatbot password-reset abuse on a major social platform. Together, the cases highlighted how quickly AI-driven services have accumulated large stores of personal data and the exposure that follows when access controls fail.
Source: Malwarebytes - https://www.malwarebytes.com/blog/news/2026/02/ai-chat-app-leak-exposes-300-million-messages-tied-to-25-million-users
