Security researchers at Tenable disclosed nine cross-tenant vulnerabilities in Google Looker Studio (formerly Data Studio), collectively dubbed LeakyLooker, that could have allowed attackers to access other tenants’ data sources and run arbitrary SQL queries against victims’ connected databases. Reported impacts included potential data exfiltration as well as the ability to insert or delete data in connected services, with attack paths described as zero-click and one-click depending on the vector. Affected connectors and services potentially included Google Sheets, BigQuery, Spanner, Cloud Storage, and third-party databases such as PostgreSQL and MySQL, reflecting Looker Studio’s broad integration surface within Google Cloud environments.
The reported issues spanned multiple classes of cross-tenant weaknesses, including unauthorized access, SQL injection via database connectors and stored credentials, BigQuery/Spanner query abuse (including via native functions and APIs), data source leakage via hyperlink and image rendering behaviors, an XS-leak using frame counting/timing oracles, and a “denial of wallet” scenario targeting BigQuery cost exposure. Google remediated the vulnerabilities following responsible disclosure (reported as June 2025), and both sources state there is no evidence of in-the-wild exploitation at the time of publication.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Tenable publicly disclosed the nine 'LeakyLooker' vulnerabilities, describing zero-click and one-click cross-tenant attack paths in Google Looker Studio. The disclosure said there was no evidence of exploitation in the wild and detailed impacts including arbitrary SQL queries, data leakage, XS-Leaks, and BigQuery 'denial of wallet' abuse.
Google fixed all reported LeakyLooker issues in its Google-managed Looker Studio service after receiving Tenable’s disclosure. Reports said customers did not need to apply patches themselves because the remediation was performed service-side.
Tenable reported nine cross-tenant vulnerabilities in Google Looker Studio to Google through responsible disclosure. The flaws affected Looker Studio’s connector and credential model and could enable cross-tenant SQL execution, data exfiltration, data tampering, and cost-amplification attacks.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.