Daily Guardian UAEDaily Guardian UAE
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
What's On

DataFlow’s TrueProfile.io Partners with MediLearning to Close the CPD Gap for Healthcare Professionals Across the GCC

August 20, 2026

A face-search tool left more than 9 million photos sitting unprotected

August 20, 2026

WSO2 Appoints Harry Ault as New CEO

August 20, 2026

Samsung locks in August 27 for its next Galaxy S phone, and all signs point to the S26 FE

August 20, 2026

YouTube is using a carrot-and-stick approach to keep top creators from cozying up to Netflix

August 20, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian UAE
Subscribe
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
Daily Guardian UAEDaily Guardian UAE
Home » A face-search tool left more than 9 million photos sitting unprotected
Technology

A face-search tool left more than 9 million photos sitting unprotected

By dailyguardian.aeAugust 20, 20263 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

That photo you uploaded to identify someone may have ended up somewhere you never expected. Security researcher Jeremiah Fowler discovered an unsecured database linked to ClarityCheck, a people-search service that says its reverse image search is “private and secure,” containing more than 9 million files, including photos of people’s faces. ClarityCheck has built its service around helping people verify strangers and decide who they can trust online, which makes a security lapse involving its own users’ uploads particularly uncomfortable.

According to Fowler’s research published by ExpressVPN, the database held roughly 450GB of data and did not require a password to access. Many of the files were stored inside folders labelled “faces” and “profiles,” and included profile photos, screenshots, and other images of adults, teenagers, and children. The storage location was reportedly accessible through a URL found in ClarityCheck’s publicly available website code. The company has since restricted access.

The people in the photos may never have used ClarityCheck

This is where the situation gets particularly uncomfortable. ClarityCheck lets someone upload a photo to search for the person shown in it, potentially returning social media profiles and other identifying information. That means the person whose face is being searched may have never visited ClarityCheck themselves.

Art, Collage, Person

Fowler says some of the images appeared to come from social media, dating profiles, screenshots, and photographs, raising the possibility that people had no idea their faces were sitting inside the database. He also reported finding files carrying timestamps beyond ClarityCheck’s stated 14-day retention period for uploaded images.

ClarityCheck says the photos weren’t really public

In a statement to WIRED, ClarityCheck pushed back on the description that the database was “publicly exposed,” arguing that access required a specific, unindexed URL. However, the files themselves were not password-protected, and Fowler found that URL in code available on ClarityCheck’s own website.

There is no evidence that anyone maliciously accessed the database before it was secured. Still, an obscure URL is not the same as a protected one, and if a security researcher could find it through publicly available code, someone else potentially could too.

ClarityCheck also had a separate security issue involving its website APIs. According to WIRED, manipulating certain ClarityCheck URLs and entering a person’s name could reveal possible email addresses, phone numbers, and physical addresses without requiring any special access.

For now, reports have not indicated that the identifying details were directly linked to the exposed photos. Even so, having your image stored in an unsecured database by a service you may never have used is a serious privacy problem, especially when AI has made impersonation, fake profiles, and scams much easier to pull off.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Samsung locks in August 27 for its next Galaxy S phone, and all signs point to the S26 FE

YouTube is using a carrot-and-stick approach to keep top creators from cozying up to Netflix

AI may be learning from billions of images without copying any one of them

Avec’s new AI feature makes sure you never miss a deadline again

Google is giving students a free year of AI Pro and a new Gemini Student Hub

You’ll have to wait until 2027 for those leaked AirPods with built-in cameras

Google gives Gemini Live its own Deep Research upgrade

Meta’s AI assistant finally lands on Mac, but it has some catching up to do

Shopping for a new Pixel 11? These are the best cases you can buy today

Editors Picks

A face-search tool left more than 9 million photos sitting unprotected

August 20, 2026

WSO2 Appoints Harry Ault as New CEO

August 20, 2026

Samsung locks in August 27 for its next Galaxy S phone, and all signs point to the S26 FE

August 20, 2026

YouTube is using a carrot-and-stick approach to keep top creators from cozying up to Netflix

August 20, 2026

Subscribe to News

Get the latest UAE news and updates directly to your inbox.

Latest Posts

Payit Introduces a More Flexible Way to Send Money Internationally

August 20, 2026

AI may be learning from billions of images without copying any one of them

August 20, 2026

Mercedes-Benz celebrates “140 Years of Innovation” with IWC Schaffhausen

August 20, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian UAE. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.