A security audit of 17 AI chatbot apps found hardcoded credentials, exposed cloud databases, and at least six apps where hackers could link explicit conversations to real user identities. The vulnerabilities remain unpatched, and the apps have been downloaded over 150 million times combined.