Millions of Android users at risk due to Gemini integration bug – these apps could be affected
Google’s Gemini integration in Android apps exposes sensitive API keys in popular apps, potentially risking user data and developer security

Google’s Gemini integration in Android apps has flagged potential data exposure risks for several Android apps. A recent report has revealed a list of apps that are at risk, including big names such as OYO Hotel Booking App, Google Pay for Business, Taobao, Apna Job Search App, and ELSA Speak: AI English Learning.
According to the findings released by Cloud SEK, a common Google API key, which was previously considered safe for client-side use, can gain significant privileges once the Gemini API is enabled, potentially allowing unauthorized access to sensitive data and services.
The Cause of the Issue
The issue erupts due to the API keys that developers generally embed in applications for general services such as Maps or Firebase. While these keys were initially designed to function as identifiers, the report claims that they can inadvertently turn into active credentials after Gemini’s generative language API is integrated. with this change a new issue arises which allows hackers to be able to extract the key by reverse engineering the app, they could gain access to Gemini endpoints without additional authentication.
Exposed API Keys Across Widely Used Applications
The report further stated that it analyzed 10,000 widely used Android applications and found dozens of exposed API keys across several apps, with a combined install base of over 500 million. The report also stated that the vulnerability builds on earlier research by Truffle Security, which pointed to similar risks before the current revelation in Google and Cloud environment.
For users, this can be serious. Data shared with Gemini-powered features, including files, images, and contextual AI interactions, can become accessible if the keys are compromised. At the same time, developers can face financial and regulatory risks as attackers can misuse these keys to make unauthorized API calls. The report further urged all developers to audit their API key usage and avoid embedding sensitive keys indiscriminately.
What Are API Keys
Application Programming Interface, or API, is a set of rules or protocols that enables software applications to communicate with each other to exchange data, features, and functionality. APIs give application owners a simple way to share their application data and functions across different departments within their organizations with ease.
It is necessary for an API to be able to validate that the application requesting the information is authorized to do so. Using API keys enables an application developer to authenticate applications that are calling an API backend to ensure they are authorized to do so.

Tesla's Cybercab to feature built-in Starlink antenna, bringing satellite internet to robotaxis
US rejects Tesla bid to avoid recall of nearly 20,000 vehicles over headlight issue
IIT Kanpur study finds no evidence E20 petrol damages engines, says mileage impact is minimal
As Nissan expands its line-up from one model to four, the carmaker is betting on affordable SUVs, exports and ICE volumes before making its EV play
Volkswagen layoffs could hit 1 lakh as CEO warns of deeper cost overhaul
