
Security researchers analyzed iPhone AI apps and found that 282 of them were carelessly leaking their internal API keys — the digital passwords that apps use to access AI services — directly in their network traffic. Anyone with the right tools could grab these keys and use the apps’ AI features for free, or in some cases access AI services under the app developer’s account.
For ordinary users, the main risk is that poorly secured apps like these tend to cut corners on privacy too. If an app can’t protect its own credentials, it may also be loose with yours. These are mostly obscure, unofficial AI chat apps rather than well-known products, but they represent a broad pattern of developers prioritizing speed over security when building AI tools.
How to check if you’re affected
Affected products include unofficial, third-party AI chat apps on iOS devices — especially smaller apps not made by major companies like OpenAI, Google, or Apple. Your risk is low if you stick to official, well-known apps:
- Open Settings → Privacy & Security on your iPhone to review what data your apps can access.
- Delete any AI chat apps you downloaded from lesser-known developers or that you no longer use.
- Stick to official AI apps from established companies (such as the official ChatGPT, Gemini, or Claude apps) rather than generic “AI chat” tools with few reviews.
