PulseAugur
EN
LIVE 21:33:51

Google's Gemini API exposed via unrestricted Firebase keys, costing thousands

A security vulnerability has been discovered where unrestricted Firebase browser keys can be used to access Gemini APIs, leading to unexpected billing spikes. One user reported a €54,000 increase in charges within 13 hours due to this issue. A script has been developed to scan Firebase projects for exposed API keys and test them against Gemini, providing a report on their status. AI

RANK_REASON A script was released to detect and mitigate a specific security vulnerability related to API key exposure.

Read on Hacker News — AI stories ≥50 points →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Google's Gemini API exposed via unrestricted Firebase keys, costing thousands

COVERAGE [1]

  1. Hacker News — AI stories ≥50 points TIER_1 English(EN) · zanbezi ·

    €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs