A security researcher finds that ClarityCheck, a people- and reverse-image search service, left more than 9 million photo files accessible online due to an unsecured Amazon S3 configuration. Reports say the exposed images include photos that appear to be face profile pictures and other personal photographs of adults, teenagers, and children. The issue is linked to folders such as “faces” and “profiles,” which could be accessed via URLs embedded in publicly available website code.

Context: ClarityCheck markets its reverse-image and people-search functions as “private and secure.” According to the reporting, the database was later secured after the company was contacted, but the researcher says the images may have been accessible for months. Additional reporting also describes a separate API or URL misconfiguration that could be manipulated to reveal personal details such as email addresses, physical addresses, and phone numbers by entering a name into crafted URLs.

Outlets differ mainly in emphasis: some focus on the large scale of the face image exposure, while others stress the other personal-data exposure path. ClarityCheck says the data was not “publicly exposed” in the sense of discoverability through ordinary search, and that restricting access happened once the issue was reported.