TechForge

April 29, 2025

Share this story:

Tags:

Categories::

  • The iOS Second Phone Number app leaked user messages, phone numbers, and contact names.
  • The app also exposed API keys and app credentials.

Researchers at Cybernews found that a virtual phone number app designed to assist users maintain privacy has exposed sensitive information due to a mis-configured database.

The app, Second Phone Number, promotes itself as a way to protect private calls and texts. However, an exposed Firebase database linked to the app revealed user data unlikely to be intended to be public.

Aras Nazarovas, an information security researcher at Cybernews, explained that the app was used for a variety of purposes, including dating and business communication. “Skilled attackers would have ample data to blackmail the app users who used it for personal purposes,” he said.

Cybernews has attempted to contact the developers behind Second Phone Number multiple times about the exposed database but has not received a response. As of the time of writing, the database remains accessible.

How many users are potentially affected?

While Apple’s App Store does not provide public download numbers, third-party estimates suggest Second Phone Number has been downloaded nearly four million times, with more than three million downloads in the United States alone.

At the time of discovery, researchers found over 700 SMS messages exposed, including sender and recipient phone numbers, and names assigned by users. However, the actual scope could be larger.

Firebase serves as a temporary database, meaning older records may not have been visible at the time of the scan but could have been accessible to bad actors earlier.

“Threat actors can set up these scrapers to constantly download sensitive data from the Firebase instance and gain real-time access to new data such as sent messages,” Nazarovas said.

The leaked data could be valuable for attackers, particularly because many users were seeking specific anonymity. Others were using the app for business purposes, and leaked information could potentially be used to hijack accounts or obtain sensitive details.

App secrets also exposed

In addition to leaking user information, the exposed Firebase database revealed several internal app secrets, including API keys, client IDs, and database URLs.

Exposing sensitive credentials makes it easier for attackers to exploit app services, potentially compromising both user data and backend systems.

Second Phone Number is not the only iOS app to face this type of vulnerability. Cybernews researchers have previously reported widespread security issues in multiple categories of apps, including dating platforms, family tracking tools, and apps designed to store private data.

A broader investigation by Cybernews involved scanning about 156,000 iOS apps—roughly 8% of the App Store inventory—and found that 71% of apps leaked at least one sensitive secret, with an average of 5.2 secrets exposed per app.

How developers can fix these issues

Researchers recommend that app developers address Firebase and hard-coded credential issues separately. “The Firebase instance used by the app was exposed and publicly accessible, allowing threat actors to connect to the database and scrape it in real-time, gaining access to information about any actions made by their users, including access to customer support communications and user-supplied AI prompts,” the Cybernews researchers said.

See also:

“Hard-coded secrets allow threat actors to enumerate infrastructure used by the app,” Nazarovas said. “If any authentication secrets are present, it may also allow threat actors to abuse the affected services to harvest user data or for other unauthorised purposes.”

Author

  • As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

    View all posts

About the Author

Muhammad Zulhusni

As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

Related

August 24, 2026

August 11, 2026

August 10, 2026

August 5, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12371 view(s)
11427 view(s)
7693 view(s)
5372 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)