ClarityCheck Database Exposes 9 Million Files - Audiolib JS
● Breaking

ClarityCheck Database Exposes 9 Million Files

ClarityCheck Database Exposes 9 Million Files - claritycheck data exposure
ClarityCheck Database Exposes 9 Million Files

ClarityCheck, a people-search tool that markets itself as private and secure, exposed more than 9 million image files containing photographs of people. The database, which held roughly 450 GB of data, was left publicly accessible on an unsecured Amazon S3 bucket. Researchers found that anyone with a web browser could view the contents, which included profile pictures, screenshots, and other images of adults, teenagers, and children.

Files were stored in folders labeled “faces” and “profiles,” and the URLs were embedded in the company’s public website code. This means the exposure wasn’t a secret backdoor; it was simply a misconfiguration that allowed direct access. The website’s own disclaimer claims that reverse image searches are private and secure, a claim that stands in stark contrast to the reality of the unsecured storage.

While ClarityCheck secured the bucket after WIRED contacted the company in July, the exposure had persisted for months. Independent security researcher Jeremiah Fowler, who discovered the issue, noted that his initial attempts to flag the problem were unsuccessful. The company moved quickly to lock the files down once the media became involved, but the data had already been available to the public.

Privacy concerns and user consent

The tool requires users to attest that they have permission to upload photos, but Fowler points out a significant gap in this process. People whose faces appeared in the exposed files may have had no idea that ClarityCheck held their images. The service is designed to identify people, so users often upload photos of others without seeking explicit consent from those individuals.

Related: Trump Picks Heidi Overton for FDA Post

Biometric data like face images is difficult to secure once it leaves a user’s device. If a photo is posted online, it can be scraped and stored in databases that are not always properly protected. The risk is amplified when these databases are misconfigured, as they become open repositories for sensitive personal information. Even if the site now requires permission, the history of unauthorized uploads remains a concern.

It is difficult to know exactly who downloaded the images during the exposure window. Because the data was indexed and accessible, it likely circulated beyond the immediate scope of ClarityCheck’s own users. This creates a long-term risk for the individuals whose images were captured in the database.

Security experts suggest that companies holding large amounts of biometric data should implement stricter access controls and monitoring. Automated scanning tools can detect misconfigured storage buckets before they become public issues. Until these measures are in place, users of people-search tools must assume their uploaded images could be vulnerable to exposure.