Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access (securityweek.com)
0xBASE INTEL BRIEF
- Thousands of Android apps contain hardcoded Google API keys.
- These keys now enable unauthorized access to Gemini AI endpoints.
- Risks include data breaches and financial losses from misuse.
"Security research identifies that thousands of hardcoded Google API keys, previously considered non-sensitive, now grant unauthorized access to Gemini AI endpoints, creating significant data exposure and financial risks."
no comments yet.