Security researchers reported that previously “non-secret” Google Cloud API keys (commonly embedded in public client-side code for services like Google Maps, YouTube embeds, Firebase, and analytics) can silently become usable credentials for Gemini (Generative Language API) endpoints once the Gemini API is enabled in the same Google Cloud project. Truffle Security described this as a privilege escalation/incorrect privilege assignment scenario where long-exposed AIza... keys—originally treated as project identifiers for billing and API access control—can unexpectedly grant access to Gemini-related data and capabilities, including access to private AI resources (e.g., uploaded files/cached context) and billable inference usage, without clear developer warning or explicit re-authorization.
Truffle Security’s internet-scale scanning (including Common Crawl) identified ~2,800–3,000 exposed keys across organizations in multiple sectors (and reportedly even from Google), highlighting the practical risk of key harvesting from page source and subsequent abuse. The primary impact described is data exposure via Gemini API access and cost/abuse risk (attackers potentially generating significant charges by making API calls). Separate from the API-key issue, Google also announced a Gemini feature update for Google Workspace that allows Gemini to search Google Chat history (noted as off by default), which is a product capability announcement rather than a vulnerability disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
A separate Quokka report found more than 35,000 unique Google API keys embedded across roughly 250,000 Android apps. The finding underscored how AI-enabled endpoints like Gemini can increase the impact of widespread API key exposure beyond websites alone.
At disclosure time, researchers said Google's mitigations reduced risk but did not fully resolve the underlying architectural problem of shared API key behavior across services. They advised organizations to audit whether Gemini was enabled, restrict and rotate exposed keys, and scan codebases for public AIza keys.
Google said it classified the issue as a single-service privilege escalation and implemented measures to detect and block leaked keys attempting to access Gemini. The company also said new AI Studio keys would default to Gemini-only scope and that affected users would be notified when leaks are detected.
By late February 2026, Truffle Security publicly reported that publicly exposed Google Cloud API keys could be abused to access Gemini APIs, potentially exposing private data and causing significant costs. The researchers said they found nearly 3,000 exposed keys across many organizations, including some associated with Google.
A startup developer reported that a compromised Google Cloud API key was abused between February 11 and February 12, 2026, generating $82,314.44 in unauthorized Gemini charges within 48 hours. The usage was said to be primarily for Gemini 3 Pro Image and Gemini 3 Pro Text.
Truffle Security scanned the November 2025 Common Crawl dataset and identified thousands of publicly exposed Google Cloud API keys. The researchers later reported that 2,800+ of these keys were still live and could authenticate to Gemini when the Generative Language API was enabled on the same project.
Researchers determined that when Gemini/Generative Language API is enabled in a Google Cloud project, existing unrestricted API keys in that project can silently gain access to Gemini endpoints. This created an order-of-events privilege escalation in which previously public-facing keys could expose Gemini files, cached content, and billable usage.
For years, Google documentation treated certain API keys used for services like Maps and Firebase as non-secret identifiers that could be embedded in client-side code. This created a large legacy population of publicly accessible AIza-format keys across websites, repositories, and apps.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcego.theregister.com
Open sourceinfosecwriteups.com
Open sourcevulnu.com
Open sourcecybersecuritynews.com
Open sourcetrufflesecurity.com
Open sourcebleepingcomputer.com
Open sourceblog.securitybreached.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.