CloudSEK

500 Million Android Users at Risk: CloudSEK Exposed Google Gemini API Keys Found Hiding in Plain Sight

Cybersecurity firm CloudSEK has uncovered 32 live Google API keys hardcoded inside 22 popular Android apps — collectively installed on over 500 million devices — that silently grant unauthorized access…

April 10, 2026
4 min read

Cybersecurity firm CloudSEK has uncovered 32 live Google API keys hardcoded inside 22 popular Android apps — collectively installed on over 500 million devices — that silently grant unauthorized access to Google’s Gemini AI platform.

If you’ve ever used apps like OYO, ELSA Speak, Shutterfly, or Taobao, your data may be more exposed than you think. A new report from CloudSEK’s BeVigil security platform reveals a systemic flaw that turns decade-old developer habits into a modern AI security nightmare.

What happened — and why it matters

For years, Google told developers that API keys in the AIza... format were safe to embed in apps — treated as public identifiers, not secrets. That assumption quietly broke when Google launched Gemini. Every existing API key on a Google Cloud project now automatically inherits access to Gemini endpoints — with no warning, no notification, and no opt-in.

Developers who embedded Maps or Firebase keys years ago, following Google’s own documentation, now unknowingly hold live credentials to one of the world’s most powerful AI systems. This is not a developer error — it’s an architectural API security failure.

CloudSEK

The 22 vulnerable apps at a glance

AppCategoryInstallsRisk noted
OYO Hotel BookingTravel100M+Live key confirmed
Google Pay for BusinessFinance50M+Live key confirmed
TaobaoE-commerce50M+Live key confirmed
apna Job SearchCareers50M+Live key confirmed
ELSA SpeakEducation10M+Data exposure confirmed
ShutterflyProductivity10M+Live key confirmed
JioSphere BrowserUtility10M+Live key confirmed
Muslim: Ramadan 2026Lifestyle10M+Live key confirmed
30 Day Fitness ChallengeHealth—Live key confirmed
ISS Live Now + othersVarious—13 more apps affected

ELSA Speak’s exposure was the most severe — CloudSEK researchers used the extracted key to query Google’s Gemini Files API and received a live list of user-uploaded audio files, likely speech recordings submitted for AI pronunciation coaching. Read more on our tech coverage for related app security stories.

What an attacker can do with one key

  • Download private user files (audio, images, documents) from the Gemini Files API
  • Make unlimited AI calls, racking up massive charges on the developer’s cloud account
  • Exhaust API quotas, breaking AI features for real users
  • Read cached AI context windows containing sensitive internal prompts
  • Persist across app updates — hardcoded keys often survive versioning

Real financial damage: three cases

CaseWhoTimeframeFinancial loss
1Solo developer, startupOvernight$15,400
2Japanese companyUndisclosed~$128,000
33-person dev team, Mexico48 hours$82,314

In the Mexico case, the team’s typical monthly cloud spend was just $180 — the attack represented a 455× spike in 48 hours. Google’s representative initially held them liable, citing the Shared Responsibility Model. The amount exceeded the company’s total bank balance. Stay updated on stories like this via TechnoSports Cybersecurity.

“This issue does not stem from developer negligence. The root cause lies in an architectural design decision, where publicly exposed identifiers were effectively elevated into AI authentication credentials without explicit communication.”— Tuhin Bose, Cybersecurity Researcher, CloudSEK

What developers should do now

If you maintain an Android app that uses any Google Cloud API key, audit it immediately. Rotate any key that has Gemini API access enabled on its project. Use environment variables or secret managers — never hardcode credentials in app bundles. Google should also proactively notify developers whose keys have silently inherited Gemini access.

Frequently asked questions

Is my data at risk if I use apps like OYO or ELSA Speak?

Potentially yes — CloudSEK confirmed live data exposure in ELSA Speak; users of any of the 22 flagged apps should watch for official security advisories from those developers.

Can Google fix this automatically without developer action?

Google can revoke compromised keys, but permanent fixes require developers to rotate credentials and adopt secure secret management practices in their apps.

Follow us on Google News Get real-time updates & exclusive tech coverage
Follow

Leave a Reply

Your email address will not be published. Required fields are marked *

wp_enqueue_script('jquery', false, [], false, true); // load in footer