logo

DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers

ID: a20f7396-8b17-57b9-8410-cb90e0c97d8b

STIX ID: report--a20f7396-8b17-57b9-8410-cb90e0c97d8b

Feed Name: Ars Technica Security

Threat Score
75/100

Date Published: 2025-02-06

Date Updated: 2026-04-19

Author: Dan Goodin

...
...

Multiple security concerns were reported for DeepSeek: researchers found the model resisted malicious prompt attacks, while security firm Wiz discovered a publicly accessible database containing over one million chat histories, backend data, API secrets and operational details with an open interface enabling full control and privilege escalation; additionally, the mobile app used insecure (HTTP) endpoints by disabling ATS, exposing data in transit, and prompting U.S. lawmakers to push for a government ban.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.