Major Google Bug Triggers Gemini AI Leak in Google Pay for Business, Oyo Hotels and Other Apps: Report

A CloudSEK report has found hardcoded Google API keys in Android apps that expose Gemini credentials.

Advertisement
Written by Akash Dutta, Edited by Ketan Pratap | Updated: 9 April 2026 17:01 IST
Highlights
  • These API keys were previously used as public identifiers
  • Gemini integration in Android apps adds authentication to the keys
  • Bad actors can steal user data and trigger unauthorised usage

CloudSEK has found 32 keys in 22 Android apps with more than 10 million installations

Photo Credit: Unsplash/Daniel Romero

Google's implementation of an application programming interface (API) key architecture has reportedly led to a massive Gemini exposure risk in Android apps. As per the cybersecurity research firm CloudSEK, a particular client-side API key, which previously functioned as an identifier, receives credential privileges after an Android app integrates the Gemini API. This, in the hands of a bad actor, can expose the data users share with the chatbot. Additionally, this can also result in bad actors making unauthorised Gemini API calls, racking up huge bills for the developer.

How a Google API Key Triggers Gemini Exposure

In a blog post, CloudSEK explained how an API key (AIza...), which was deemed safe by Google to add to the codebase of Android apps, suddenly gains credential privileges after Gemini is integrated into the app. This security flaw builds on the findings of Truffle Security, which found a similar flaw on a Google Cloud project.

Advertisement

CloudSEK's BeVigil, a mobile app security search engine, scanned the top 10,000 Android apps (based on number of installs) and found 32 live Google API keys hardcoded in 22 different apps with more than 500 million installs collectively. Some of these apps are Oyo Hotel, Google Pay for Business, Taobao, apna Job Search App, Elsa Speak, HD Sticker & Pack WAStickersApps, The Hindu, ISS Live Now, and more.

Interestingly, the report claims that the API key format Alza… is added to the app when a developer wants to embed Maps or Firebase, as per the documentation instructions shared by Google. However, after enabling the Generative Language API, the key gains access to all Gemini endpoints without any warning or notification. So, anyone who decompiles the app can easily gain access to the key, and it acts like a live Gemini credential.

Advertisement

For end users, this means any data shared with Gemini, such as documents, images, or audio, and stored in the Files API, can be accessed by the bad actor. Additionally, all sensitive information in the cached AI context can be read, copied, or exfiltrated by the one gaining unauthorised access.

Developers and publishers also face significant risks. Gemini API integration is not free. Developers pay for any usage. So, if the bad actor ends up making unauthorised usage, it can rack up massive bills. Additionally, this also puts a regulatory burden on the companies if the users' data is compromised.

Advertisement

CloudSEK recommends developers and companies review all API keys in a GCP project, rotate any key that is embedded in a mobile app, restrict keys by service, and not hardcode any API key in the mobile app source code. While end users cannot do much, they should be careful about using Gemini services in an Android app. If they do not trust the app, they should limit their Gemini interaction to the official app and platforms.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. What Is Anthropic's Claude Mythos and What Can It Do?
  2. OTT Releases This Week: O'Romeo, Tu Yaa Main, Main Wo Aur Fuji, Thaai Kizhavi, and More
  3. Ai+ Nova 2 Ultra Launched in India Alongside Ai+ Nova 2: See Prices
  4. Vivo V70 FE Goes on Sale in India With These Offers
  5. Oppo Find X9s Pro Design Renders, Colourways Leaked Ahead of April 21 Launch
  6. Ai+ Nova Flip 5G Launched in India With 50-Megapixel Main Camera: See Price
  7. OnePlus Nord 6 With 9,000mAh Battery Is Now Available to Purchase in India
  8. Realme C100 4G Launched With 8,00mAh Battery, 50-Megapixel Rear Camera
  9. Samsung Might Host Its Galaxy Z Fold 8 Launch Event in This City
  1. Realme C100 4G Launched With 8,00mAh Battery, 50-Megapixel Rear Camera: Price, Features
  2. Samsung's Galaxy Unpacked Event Details for Galaxy Z Fold 8, Galaxy Z Fold 8 Wide Launch Leaked: See Expected Date, Location
  3. Vivo T5 Pro 5G Colour Options Revealed as Launch in India Draws Near
  4. Stablecoin Transactions Could Reach $1.5 Quadrillion Mark by 2035, Chainalysis Claims
  5. iQOO 16 Will Feature Flagship Snapdragon 8 Elite Gen 6 Pro Chip and Samsung Display, Tipster Claims
  6. Major Google Bug Triggers Gemini AI Leak in Google Pay for Business, Oyo Hotels and Other Apps: Report
  7. Motorola Edge 70 Pro Leak Reveals Design, Colourways as HDR10+ Database Listing Hints at India Debut
  8. Blockchain Sleuth Claims DPRK Unit Made $1 Million a Month Posing as Crypto IT Workers
  9. Oppo Find X9s Pro Design and Colour Options Seen in Leaked Renders Ahead of April 21 Launch
  10. OnePlus Nord 6 With 9,000mAh Battery, 50-Megapixel Camera Goes on Sale in India: Price, Offers
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.