AI Privacy IncidentJanuary 20, 2026

Chat and Ask AI Firebase misconfiguration exposes 300 million user messages

Vendor: Codeway
Product: Chat & Ask AI
Severity: high
Status: confirmed-resolved
Users affected: approximately 25 million users; approximately 300 million messages

Summary

On January 20, 2026, independent security researcher Harry identified a Firebase misconfiguration in Chat & Ask AI, a multi-model AI chat application developed by Turkish firm Codeway with more than 50 million installs across Google Play and the Apple App Store. The app routes user conversations to ChatGPT, Google Gemini, and Claude. The misconfiguration left Firebase Security Rules set to public, exposing approximately 300 million messages from 25 million user accounts to unauthenticated read, write, and delete access. Codeway resolved the issue across all of its applications within hours of Harry's report.

What happened

  • Harry, using an automated Firebase-scanning tool he built called Firehound, identified Codeway's Firebase project as publicly accessible without authentication.
  • The project's Security Rules allowed any party to read, modify, or delete the stored data without credentials.
  • Exposed records included users' complete chat histories, the AI models used in each session, and application settings. Malwarebytes reported that some conversations involved sensitive personal topics.
  • Additional applications by the same developer shared the same Firebase project and were exposed in the same configuration.
  • Harry reported the issue to Codeway on January 20, 2026. The company resolved the misconfiguration across all affected applications within hours.
  • Malwarebytes published Harry's findings on February 9, 2026.
  • Harry's broader Firehound scan of 200 popular iOS applications found that 103 had the same Firebase misconfiguration, collectively exposing tens of millions of files.

Timeline

  • 2026-01-20 -- Harry identifies the Firebase misconfiguration and reports to Codeway.
  • 2026-01-20 -- Codeway remediates the issue within hours across all affected applications.
  • 2026-02-09 -- Malwarebytes publishes Harry's research findings.

What remains unclear

  • The duration of the misconfiguration before January 20, 2026, has not been disclosed.
  • Codeway has not confirmed whether any third party accessed the data before remediation.
  • Codeway has not issued a public statement on the incident.

Broader context

AI chat applications that route conversations through multiple underlying model APIs and log results in a shared cloud database create a single point of exposure for the combined conversation history of all model integrations. Firebase's default Security Rules require an active configuration step to restrict database access, and the gap between deployment and that step has been the source of similar exposures across the mobile application ecosystem.

Sources

Selvam Sivakumar
Written by

Selvam Sivakumar

Founder, Elephas.app

Selvam Sivakumar is the founder of Elephas and an expert in AI, Mac apps, and productivity tools. He writes about practical ways professionals can use AI to work smarter while keeping their data private.

Related Resources

news

The Open Weights Fight: What NVIDIA, Anthropic, and Meta Are Really Arguing About

133 companies signed a letter defending open weight AI models. Anthropic pushed back. Zuckerberg made a third argument. Here is what each side really wants, and the one party none of them argues about.

15 min read
news

Claude Shared Chats and Google: The Explanation Has a Gap

Claude shared chats and Google search: the robots.txt explanation everyone repeated lists a bare URL, not a readable chat. What we checked on 27 July 2026.

13 min read
news

Apple Sues OpenAI: The Lawsuit Everyone Thought Would Go the Other Way

Apple filed a trade-secret lawsuit against OpenAI on July 10, 2026, naming hardware chief Tang Tan and engineer Chang Liu. Two months earlier OpenAI was the one weighing a case against Apple, and never filed. What the complaint alleges, how OpenAI responded, and the Musk-Altman fallout.

9 min read
news

ToqanClaw Brings Private AI to 5 Million Businesses

Prosus launched ToqanClaw, a private AI for five million businesses. Here is how Elephas gives Mac and iPhone users the same private AI assistant, with on-device redaction.

9 min read