Major Google Bug Triggers Gemini AI Leak in Google Pay for Business, Oyo Hotels and Other Apps: Report

A CloudSEK report has found hardcoded Google API keys in Android apps that expose Gemini credentials.

Advertisement
Written by Akash Dutta, Edited by Ketan Pratap | Updated: 9 April 2026 17:01 IST
Highlights
  • These API keys were previously used as public identifiers
  • Gemini integration in Android apps adds authentication to the keys
  • Bad actors can steal user data and trigger unauthorised usage

CloudSEK has found 32 keys in 22 Android apps with more than 10 million installations

Photo Credit: Unsplash/Daniel Romero

Google's implementation of an application programming interface (API) key architecture has reportedly led to a massive Gemini exposure risk in Android apps. As per the cybersecurity research firm CloudSEK, a particular client-side API key, which previously functioned as an identifier, receives credential privileges after an Android app integrates the Gemini API. This, in the hands of a bad actor, can expose the data users share with the chatbot. Additionally, this can also result in bad actors making unauthorised Gemini API calls, racking up huge bills for the developer.

How a Google API Key Triggers Gemini Exposure

In a blog post, CloudSEK explained how an API key (AIza...), which was deemed safe by Google to add to the codebase of Android apps, suddenly gains credential privileges after Gemini is integrated into the app. This security flaw builds on the findings of Truffle Security, which found a similar flaw on a Google Cloud project.

Advertisement

CloudSEK's BeVigil, a mobile app security search engine, scanned the top 10,000 Android apps (based on number of installs) and found 32 live Google API keys hardcoded in 22 different apps with more than 500 million installs collectively. Some of these apps are Oyo Hotel, Google Pay for Business, Taobao, apna Job Search App, Elsa Speak, HD Sticker & Pack WAStickersApps, The Hindu, ISS Live Now, and more.

Interestingly, the report claims that the API key format Alza… is added to the app when a developer wants to embed Maps or Firebase, as per the documentation instructions shared by Google. However, after enabling the Generative Language API, the key gains access to all Gemini endpoints without any warning or notification. So, anyone who decompiles the app can easily gain access to the key, and it acts like a live Gemini credential.

Advertisement

For end users, this means any data shared with Gemini, such as documents, images, or audio, and stored in the Files API, can be accessed by the bad actor. Additionally, all sensitive information in the cached AI context can be read, copied, or exfiltrated by the one gaining unauthorised access.

Developers and publishers also face significant risks. Gemini API integration is not free. Developers pay for any usage. So, if the bad actor ends up making unauthorised usage, it can rack up massive bills. Additionally, this also puts a regulatory burden on the companies if the users' data is compromised.

Advertisement

CloudSEK recommends developers and companies review all API keys in a GCP project, rotate any key that is embedded in a mobile app, restrict keys by service, and not hardcode any API key in the mobile app source code. While end users cannot do much, they should be careful about using Gemini services in an Android app. If they do not trust the app, they should limit their Gemini interaction to the official app and platforms.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Indian Festival Sale Starts Tomorrow: Check Top Phone Deals
  2. Garmin Cirqa Smart Band Launched in India With These Features
  3. Free International Roaming Comes to All Airtel Postpaid Plans
  4. Vivo V80 Launches in India With These Features
  5. Xbox Secures Non-Exclusive Cloud Streaming Rights for GTA 6
  1. Wikimedia Says Suspected OpenAI AI Agents Generated Millions of Requests, Made Unauthorised Edits: Report
  2. Google Unveils EmbeddingGemma 2 With Multimodal Search and On-Device AI Support; Nano Banana 2.1 Announced
  3. Airtel Announces Free International Roaming on All Postpaid Plans With 5GB Data, 60 Minutes Calls
  4. Bitcoin Struggles Below $87,000 Despite Rising Whale Accumulation
  5. GTA 6 Will Get Xbox Cloud Gaming Support on Xbox Series S/X, but Will Not Stream on PC
  6. Facebook Reportedly Testing New Reels-First Experience in India Putting Video Front and Centre
  7. HMD Slate Tab 5G Design Leaks Again, Could Feature Huge 15.6-Inch Display, POGO Pins, and More
  8. Microsoft Surface Laptop Ultra Price Details Leaked Ahead of Launch; Specifications Tipped Alongside
  9. Amazon Great Indian Festival Smartphone Deals: Samsung Galaxy S25 Ultra, iPhone 16 Get Big Discounts
  10. Sony’s Next PlayStation Portal May Get an OLED Screen, New Listings Suggest
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.