Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

The Kardashians’ new websites mistakenly publicized personal user info

Add as a preferred source on Google

In conjunction with the release of their new apps, which allow fans to subscribe to exclusive content from the celebrities for a nominal monthly fee, the Kardashian-Jenner sisters have decided to each launch their own new websites this week. Of course, signing up as an early adopter of just about anything, there’s always the risk of something bad happening as a result.

In the case of the new Kardashian sites, you were opening a window to your personal data. But you’re not alone. In fact, the names and email addresses of about 891,340 users were exposed due to a flaw in the code which left the API open for everyone to see. This was discovered only a few hours after the apps and websites launched, with 19-year-old Web developer Alaxic Smith discovering the hole.

Recommended Videos

As the creator of his own community-driven, celebrity-focused app, Communly, Smith decided to start meddling in the sisters’ code to compare the data they were collecting to his own. Little did he know, the personal information of all their registrants would be so easily accessible, an amateur hacker’s dream come to life.

“I now had access to the first names, last name, and email addresses of the 663,270 people who signed up for Kylie Jenner’s website,” Smith wrote in a Medium post. “I then noticed that I could do the same API call across each of the websites and return the same exact data for each site. I also had the ability to create/destroy users, photos, videos, and more. It’s clear why this is a major issue, and raises the question: Should users trust not only their personal information but also payment information with these apps?”

Fortunately, Smith reached out to Whalerock Digital Media, the company behind the sites and apps who initially made him take the Medium post down while cautioning against speaking with the media about the security oversight. After that, the media agency assured Tech Crunch that the problem has been fixed and that any payments made prior to the patch have been secured.

In case you are one of those affected, the most harm you can expect is a few spam emails since no credit card information was leaked. And unless you’ve never agreed to a privacy policy without reading it, there’s a good chance you receive some of those already. In closing, while you shouldn’t expect this to be another Ashley Madison ordeal, it can always be a bit frustrating when your personal info has been outed.

Gabe Carey
A freelancer for Digital Trends, Gabe Carey has been covering the intersection of video games and technology since he was 16…
YouTube’s AI-powered search is rolling out in the US to find videos based on situations you describe
Ask YouTube can find videos based on the situation or idea you describe
youtube ai search feature

YouTube users in the U.S. are getting a new way to search for videos on the web. The company has started rolling out Ask YouTube, its conversational AI search experience, beyond the Premium-only test announced at Google I/O 2026.

Instead of entering a few keywords and scrolling through a standard list of results, users can ask YouTube a complete question. The feature is designed for broader searches where the exact video, channel, or topic may not already be clear.

Read more
Meta’s detection tool fails to identify photos generated by its own Muse Image AI
Meta has created an invisible watermarking tool called Content Seal that is embedded in all images generated by the Muse Image AI.
Meta AI identification tool.

Earlier this week, Meta announced two new AI products, namely, Muse Image and Muse Video. As the name suggests, these are generative AI tools for making photos and video clips using natural language text prompts. Soon after their rollout commenced, these tools sparked controversy because Meta had automatically opted in Instagram users, allowing others to use their publicly posted media and convert them into remixed AI content. But it appears that Meta courted another loss on its side of the court.

What's the problem?

Read more
Your Google AI Studio apps can finally have polished, presentable web links
AI Studio web apps can now use personalized subdomains
google ai studio logos

Google AI Studio has made building a web app surprisingly easy. You can describe what you want, refine the design through prompts, and publish the result without setting up a traditional development environment. An awkward point of friction comes after deployment, when the finished app still has to live behind a long, forgettable Cloud Run link.

Google is now cleaning up that final step. AI Studio lets you assign a deployed web app a personalized address under the “ai.studio” domain, such as “your-app-name.ai.studio.” A recognizable URL should make the project look more presentable in a portfolio, client demo, social post, or internal project page.

Read more