Cloud · 199 days ago
Truffle Security found 2,863 public Google Cloud API keys embedded in client-side code that gain access to Gemini after the Generative Language API is enabled.
3 sources covering this story
Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement
Research reveals 2,863 public Google API keys can access Gemini endpoints, enabling data exposure and massive billing abuse.
‘Silent’ Google API key change exposed Gemini AI data
Billing ID keys were turned into Gemini authentication credentials without informing developers.
Previously harmless Google API keys now expose Gemini AI data
Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI assistant and access private data.
Part of the PlainSec briefing for 2026-03-01