logo

Google API Keys Quietly Gain Access to Gemini on Android Devices

ID: 46fa0841-17d0-5d9d-ab22-9459114a4e4f

STIX ID: report--46fa0841-17d0-5d9d-ab22-9459114a4e4f

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

...
...

A CloudSEK advisory reports that Google's long-standing public API key format can silently gain access to Gemini AI endpoints when Gemini is enabled in a project, exposing embedded keys in Android apps and allowing unauthorized access to user data, unexpected charges, and service disruption. Analysis of 10,000 apps found 32 active keys across 22 applications (collectively >500 million installs), with demonstrated access to user-uploaded audio files and reported financial losses up to $128,000; researchers advise auditing, rotating keys, and restricting API access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.