logo

Previously harmless Google API keys now expose Gemini AI data

ID: 5ee1082d-e7e9-5f47-a0ff-1201ca1f4538

STIX ID: report--5ee1082d-e7e9-5f47-a0ff-1201ca1f4538

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2026-02-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers at TruffleSecurity found nearly 2,800 publicly exposed Google API keys embedded in client-side code that, due to changes when Google introduced the Gemini AI assistant, can be used to authenticate to Gemini and access private data or generate costly API usage; Google has been notified and implemented mitigations to block leaked keys and change default key scopes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.