
Public Google API keys unlock Gemini AI data risk
Researchers found nearly 3,000 Google API keys publicly exposed in client-side code that could authenticate to Google's Gemini AI and access private data. Google says it has implemented protections to block leaked keys from Gemini and will notify developers, who should audit and rotate keys. The exposure was uncovered by TruffleSecurity via the November 2025 Common Crawl dataset, highlighting potential abuse where attackers could incur API charges by making Gemini calls.













