Wondershare RepairIt Vulnerabilities Allow Hackers to Steal User Data and Hijack AI Models

# Critical Security Flaws in Wondershare RepairIt Expose User Data and AI Models to Cyber Attacks

Cybersecurity researchers at Trend Micro have uncovered two severe security vulnerabilities in Wondershare RepairIt, a popular AI-powered data repair and photo editing application. These flaws not only compromise user privacy but also create dangerous opportunities for supply chain attacks and AI model manipulation.

## The Vulnerabilities

The two critical security flaws discovered are:

– **CVE-2025-10643** (CVSS score: 9.1) – Authentication bypass through storage account token permissions
– **CVE-2025-10644** (CVSS score: 9.4) – Authentication bypass through SAS token permissions

Both vulnerabilities allow attackers to completely bypass authentication systems, potentially leading to arbitrary code execution on users’ devices through supply chain attacks.

## Privacy Violations and Poor Security Practices

The investigation revealed that Wondershare RepairIt violated its own privacy policy by collecting and storing private user data through inadequate security practices. The application embedded overly permissive cloud access tokens directly in its code, granting unauthorized read and write access to sensitive cloud storage.

Most concerning, user data was stored without encryption, leaving uploaded images and videos vulnerable to abuse. The exposed cloud storage contained not just user data, but also AI models, software binaries, container images, scripts, and company source code.

## AI Model Tampering Risks

The security flaws create a particularly dangerous scenario for AI model manipulation. Since the application automatically downloads and executes AI models from unsecured cloud storage, attackers could:

– Modify AI models or their configurations
– Distribute malicious payloads through legitimate software updates
– Infect users unknowingly through tampered AI model downloads

“Such attacks could distribute malicious payloads to legitimate users through vendor-signed software updates,” the researchers warned.

## Broader Implications

Beyond immediate data exposure, these vulnerabilities pose serious long-term risks including:

– Intellectual property theft
– Regulatory penalties
– Loss of consumer trust
– Supply chain contamination affecting downstream customers

## Vendor Response and User Recommendations

Trend Micro responsibly disclosed these vulnerabilities through their Zero Day Initiative in April 2025, but has yet to receive a response from Wondershare despite repeated attempts. Until a fix is available, users are advised to “restrict interaction with the product.”

## Growing AI Security Concerns

This incident highlights broader security challenges in the rapidly evolving AI landscape. Recent research has identified multiple attack vectors in AI systems:

– **Model Context Protocol (MCP) vulnerabilities** – Exposed servers without authentication can provide unauthorized access to sensitive data
– **Container registry attacks** – Exposed registries allow attackers to extract, modify, and replace AI models
– **Indirect prompt injection** – AI code assistants can be tricked into executing malicious code through contaminated external data
– **”Lies-in-the-loop” attacks** – Attackers can manipulate AI agents to misrepresent dangerous operations as safe

## The Security-Innovation Balance

The rush to bring AI-powered features to market often overlooks critical security implications. As Trend Micro researchers noted, “The need for constant innovations fuels an organization’s rush to get new features to market, but they might not foresee the new, unknown ways these features could be used.”

This case underscores the critical importance of implementing robust security processes throughout the development pipeline, especially for AI-powered applications that handle sensitive user data and execute code automatically.

The Wondershare RepairIt vulnerabilities serve as a stark reminder that as AI technology advances, security practices must evolve alongside to protect users and maintain trust in these powerful new tools.

Share This Article