Exposed Google API keys previously not considered secrets can now inadvertently grant attackers access to sensitive Gemini API endpoints.
Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI ...