Skip to content

Firebase · 2025-07

Tea app, first breach

An unprotected storage instance exposed tens of thousands of user images, including identity documents.

Last updated 2025-07
Not verified

What the sources report

The sources report an unprotected Firebase storage instance.

Tens of thousands of user images were exposed.

The exposed files included government-issued identity documents.

Root cause class

Storage exposure

Covered by

What ShipReady can say

A check from outside reads what a visitor can reach. Storage rules sit behind the app, so this one stays Not verified until a Launch Review looks at the bucket policies.

Sources

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026