Darkreading
Google API Keys Remain Active for Up to 23 Minutes After Deletion
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Research by Aikido Security reveals that Google API keys can remain active for up to 23 minutes post-deletion, contrary to user expectations of immediate revocation. This delay allows attackers with leaked keys to continue accessing sensitive services, including Gemini, during this window. Aikido's tests showed a median revocation window of around 16 minutes, with significant variability based on server location. The findings highlight a critical vulnerability in Google's infrastructure, as attackers can exploit this delay to run up charges or exfiltrate sensitive data. Google has not provided a fix for this issue, which poses a serious risk to organizations relying on API keys for access control. The problem is compounded by Google's billing policies that can lead to unexpected charges for users. This situation mirrors a previously reported issue with AWS access keys, where a four-second window allowed for similar exploitation.
Key Points: • Google API keys can remain valid for up to 23 minutes after deletion. • Attackers can exploit this delay to access sensitive data and incur unexpected charges. • Google has not addressed this vulnerability, leaving users at risk.