Darkreading
Google API Keys Remain Active for Up to 23 Minutes After Deletion
Article Content
Research by Aikido Security reveals that Google API keys can remain active for up to 23 minutes post-deletion, contrary to user expectations of immediate revocation. This delay allows attackers with leaked keys to continue accessing sensitive services, including Gemini, during this window. Aikido's tests showed a median revocation window of around 16 minutes, with significant variability based on server location. The findings highlight a critical vulnerability in Google's infrastructure, as attackers can exploit this delay to run up charges or exfiltrate sensitive data. Google has not provided a fix for this issue, which poses a serious risk to organizations relying on API keys for access control. The problem is compounded by Google's billing policies that can lead to unexpected charges for users. This situation mirrors a previously reported issue with AWS access keys, where a four-second window allowed for similar exploitation.
Key Points: • Google API keys can remain valid for up to 23 minutes after deletion. • Attackers can exploit this delay to access sensitive data and incur unexpected charges. • Google has not addressed this vulnerability, leaving users at risk.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.