Who is responsible for security vulnerabilities in AI-designed apps?
BEST-BACKGROUNDS – shutterstock.com
As revealed by security researcher Dor Zvi and his cybersecurity company Red Access in an interview with Axios, thousands of AI-powered web apps expose sensitive corporate and personal data unprotected on the internet.
The experts checked apps that were created using AI tools such as Lovable, Replit, Base44 and Netlify. Basically, these services allow users to create and publish web apps using AI and simple text commands.
Access up to admin rights
According to Red Access, over 5,000 of these apps built with Vibe coding had fundamental security or authentication flaws. In many cases, knowing the app URL was enough to access the content. Around 40 percent of the apps also contained sensitive information – including medical data, financial documents, company strategies and customer conversations.
