logo

Google API Keys Leak Sensitive Data Without Warning via Gemini

ID: ce8aa25f-a463-57f2-912b-5269ca465433

STIX ID: report--ce8aa25f-a463-57f2-912b-5269ca465433

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-27

Date Updated: 2026-04-22

Author: Divya

...
...

Security researchers found that legacy public Google API keys—originally safe as public billing identifiers—can be silently upgraded to grant access to Google’s Gemini generative AI when the Generative Language API is enabled on a project, allowing attackers who scrape exposed keys to access private datasets, cached contexts, and execute billable AI queries; organizations are advised to audit projects, rotate exposed keys, and restrict key scope.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.