Write storage rules that validate the file, not just the user: cap request.resource.size, restrict request.resource.contentType to the types you expect, and do not grant delete to clients unless the feature needs it. Test the rules against the emulator with adversarial uploads before publishing.

Context: Web (project README, Firebase starter): their storage.rules use public read, validated create, and no delete, with the note that the Firebase config ships inside the app bundle, so anyone with the app can exercise whatever the rules allow. A write rule that checks who but never what lets clients upload unbounded files of any type. The fix is validating request.resource.size and request.resource.contentType on create, and withholding delete grants entirely for user content.