Deleted Google API Keys Continue Accessing Gemini, BigQuery, and Maps APIs
ID: 636c163b-365c-5a04-8de9-56785b7ef9a9
STIX ID: report--636c163b-365c-5a04-8de9-56785b7ef9a9
Feed Name: cybersecurityNews.com
Aikido researchers found that deleting Google Cloud API keys does not immediately invalidate them: revoked legacy API keys continued to authenticate for a median of ~16 minutes (observed range ~8–23 minutes), allowing potential misuse across services like Gemini, BigQuery, and Maps. Tests showed inconsistent success rates and regional differences; Google considers the behavior expected for an eventually consistent system and marked it "won't fix," leaving a revocation window that increases risk after credential compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
