LIVE · cybersecurity feed
Live wire
security

Meta Ran Ads for an App That Promised to Nudify Female Politicians

One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.

zeroday.news ·

Meta platforms recently hosted advertisements for an AI-powered image generation tool called Kromix, which appeared to encourage users to create deepfake videos of female US politicians in sexually explicit scenarios. The ads ran despite Meta's stated policies prohibiting sexual material and nonconsensual intimate imagery.

The Tech Transparency Project (TTP) discovered the ads, which were exclusively targeted at male users with the tagline "Unleash Next-gen AI Magic." One video advertisement, reviewed by TTP, featured a voice-over promoting Kromix as having "no restrictions" and stating that "all the characters are real people," describing it as "the AI that men actually use." Another ad showed a woman closely resembling a prominent female US politician in front of US flags, with the caption "What if she moved?" The ad then transitioned to a scene of a woman with the same face performing in a pornographic video.

According to Meta's ad library, the account associated with this campaign ran 32 ads, each active for durations ranging from five to 46 hours. Most of these ads received ten or fewer impressions. The ad campaign was removed after Meta was contacted for comment.

Kromix, which was available on Apple's App Store, invited paid users to upload photos for use in scenarios including "bedroom rape" and "Disney love." The app also featured AI-generated pornographic videos of women in Spider-Man costumes. Apple removed the Kromix app from its App Store following an inquiry, stating that the app appeared to have added prohibited content and features after its initial review. Apple's App Review Guidelines strictly prohibit apps designed to generate, distribute, or consume pornography, as well as "nudification" apps.

Meta's public documentation indicates that all ads on its platforms, including Instagram and Facebook, are reviewed against its policies before publication, primarily using automated tools. The company has specific policies against ads containing sexual imagery, including nudity, sexual activity, or sexually suggestive content, and prohibits the promotion of "nudify" or "AI kissing" apps.

However, ads for nudify or undressing apps have frequently appeared on Meta's platforms. Between November of the previous year and January, Meta reported removing 344,000 ads promoting such services on Facebook and Instagram and has initiated legal action against at least one firm. Meta acknowledged that advertisers employ adversarial tactics, such as using benign cover photos of beaches or mountains to obscure pornographic content, to evade detection. The company stated it is investigating how these specific ads bypassed its systems.

The page running the Kromix advertisements was created on August 3 and had no followers, which could have been indicators of suspicious activity. This incident is part of a broader trend of AI-generated nonconsensual intimate imagery targeting politicians, predominantly women. In January, AI tools were used to create approximately 3 million sexualized images of women and girls, with officials in Sweden, England, and Northern Ireland among those targeted.

This is not the first instance of Meta platforms hosting problematic content. Previously, researchers found over 50 ads on Meta's platforms containing AI child sexual abuse material and sexually suggestive images of minors, some involving "face-swapping" children into sexual acts. These ads ran between November 2025 and August, reaching thousands of individuals in the US, UK, and several European countries. After being contacted, Meta removed these ads, citing violations of policies on child sexual abuse and exploitation material, and adult sexual solicitation and nudity. Some of these ads were published after Meta claimed to have introduced new AI technology to improve detection and blocking of violating ads. Several linked to an app called MaskAI, which also appeared on the App Store and was subsequently removed.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

University of Texas forced to take systems offline in San Antonio after cyberattack

The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response.

vulnerabilitycritical

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

phishinghigh

CISA gives feds 3 days to fix actively exploited Ray RCE bug

Phishing, malvertising attacks could target devs to gain access to private corporate networks

breach

BGP Role model: tracking the adoption of RFC 9234

RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.

security

Hackers target Ukrainian agency managing assets seized from sanctioned Russians

The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.

vulnerabilitycritical

NASA Ground Control Software Flaw Enables Unauthenticated Commands

Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers