The Cybernews research team has uncovered data leak involving Fitify, a popular fitness app with over 25 million installs globally. Researchers discovered that 373,000 sensitive user files — including 138,000 progress photos — were stored in a publicly accessible Google Cloud bucket — with no password protection or encryption at rest, meaning anyone could access them.
Among the leaked files were:
206,000 user profile photos
138,000 progress pictures uploaded by users to track fitness changes
13,000 AI coach message attachments, which may include images or text
6,000 body scan files, including photos and AI-generated metadata (e.g., lean mass, body fat, posture)
Key research highlights
Many of the exposed photos were semi-nude body scans, captured by users trying to document weight loss or muscle growth.
Fitify promises encryption in transit, but the lack of basic access controls poses serious privacy risks.
Researchers also found hardcoded secrets embedded in the app’s code — including Google API and Client IDs, Firebase database URLs, Facebook tokens, and even an Algolia API key, which wasn't disclosed in the privacy policy.
These exposed credentials could let attackers access backend infrastructure, impersonate users, or inject malicious content.
iOS Fitness app Fitify exposes 138K user private photos
Forum rules
1) This is a Christian site, respect our beliefs and we will respect yours.
2) This is a family friendly site, no swearing or posting offensive links, pictures, or signatures.
3) Please be respectful of others.
4) Trolls are not welcome and will be dealt with accordingly.
5) No racial comments, jokes or images
6) If you see a dead thread over 6 months old, let it rest in peace
7) No Duplicate posts
1) This is a Christian site, respect our beliefs and we will respect yours.
2) This is a family friendly site, no swearing or posting offensive links, pictures, or signatures.
3) Please be respectful of others.
4) Trolls are not welcome and will be dealt with accordingly.
5) No racial comments, jokes or images
6) If you see a dead thread over 6 months old, let it rest in peace
7) No Duplicate posts
- ccgr
- Site Admin
- Posts: 39512
- Joined: Wed May 25, 2005 12:00 am
- Are you human?: Yes!
- Location: IL
- Contact: