Previously harmless Google API keys now expose Gemini AI data
ID: 5ee1082d-e7e9-5f47-a0ff-1201ca1f4538
STIX ID: report--5ee1082d-e7e9-5f47-a0ff-1201ca1f4538
Feed Name: Bleeping Computer
Threat Score
Researchers at TruffleSecurity found nearly 2,800 publicly exposed Google API keys embedded in client-side code that, due to changes when Google introduced the Gemini AI assistant, can be used to authenticate to Gemini and access private data or generate costly API usage; Google has been notified and implemented mitigations to block leaked keys and change default key scopes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
