New "LeakyLooker" Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries
ID: 19cd9c4c-4c85-545f-93a9-2e5aee150d01
STIX ID: report--19cd9c4c-4c85-545f-93a9-2e5aee150d01
Feed Name: The Hacker News
Cybersecurity researchers disclosed nine cross-tenant vulnerabilities in Google Looker Studio, collectively named **LeakyLooker**, that could have allowed attackers to run arbitrary SQL queries and exfiltrate, modify, or delete data across Google Cloud services (BigQuery, Sheets, JDBC-connected databases, Cloud Storage, etc.). The flaws could enable attackers to access datasets and projects across tenants via public or shared reports (including cloning reports that retain owner credentials) and one-click exfiltration techniques; Google addressed the issues after responsible disclosure and there is no evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
