
Popular Android voice chat app OyeTalk with over five million downloads on Google Play, has left its database unprotected, exposing more than 500MB of private conversations and user data, including unencrypted chats, usernames, and IMEI numbers.
According to sources, the app was found to be leaking unencrypted data through unprotected access to Firebase, which is Google’s mobile application development platform that provides cloud-hosted database services.
According to reports, the app developers neglected to lock down public access to the database despite being informed of the data leak. Google’s security measures had to intervene to shut down the database because the spill became too large.
The developers also carelessly hardcoded sensitive data into the application’s client side, such as a Google API key and links to Google storage buckets. Researchers cautioned that if the leaked data had not been backed up, malicious actors could have permanently lost users’ private messages by deleting the dataset.
Notably, the OyeTalk app has previously experienced data leaks, and its database has been identified as susceptible to leaks by unidentified parties.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543