With the recent #Tea app breach, one of them was an unsecured Firebase bucket where photos where stored for verification
Uncategorized
1
Posts
1
Posters
0
Views
-
With the recent #Tea app breach, one of them was an unsecured Firebase bucket where photos where stored for verification
So bascially everyone could read/write to the bucket aka download the images
Also, the EXIF data was still included on these photos to make it even worse
~13 000 images till 2024
The second bug gave users access tp an API key that could request any data from the database
It's bad