Not hypothetically. Public incidents keep following the same script — and none of them took a genius to exploit. All of them took under an hour to prevent.
July 2025
Tea
Firebase storage bucket left open with directory listing on.
~72,000 images leaked — including 13,000 selfies and government IDs — then 1.1 million private messages in a second breach days later.
“Default storage settings are not security settings.”
Reported by Engadget ↗March 2025 · CVE-2025-48757
170+ Lovable apps
Missing Row Level Security in AI-generated Supabase backends.
A scan of 1,645 showcase apps found 1 in 10 exposing user data: names, emails, financial records, API keys. One app alone exposed 18,000 users.
“The AI writes the query. It does not ask who is allowed to run it.”
Reported by Superblocks ↗March 2025
Enrichlead
“Zero hand-written code” SaaS with API keys in the frontend and no rate limiting.
Subscriptions bypassed, keys maxed out, data manipulated. Shut down within a week of the viral launch post.
“A paywall the server never checks is a suggestion, not a paywall.”
Reported by Pivot to AI ↗July 2025
Base44
Auth bypass on the platform itself: a public app_id was enough to mint a verified account.
Private enterprise apps — HR tools, internal chatbots — open to anyone, SSO bypassed. Found by Wiz researchers; patched in 24 hours.
“Even the platform under your app is somebody’s first draft.”
Reported by Wiz Research ↗