Google Looker Studio Flaw Let Attackers Steal Data
Google Looker Studio experienced a significant flaw, dubbed “LeakyLooker,” revealing vulnerabilities that allowed attackers to exfiltrate data from Google services. Researchers identified these as a set of nine cross-tenant vulnerabilities within the platform, enabling malicious actors to execute SQL queries, alter data, or even delete records across Google Cloud without user consent. The flaw stemmed from Looker Studio’s dual authentication model, which created exploitable attack paths under both “Owner” and “Viewer Credentials.”
A notable 0-click vulnerability allowed attackers to issue SQL commands by manipulating server-side requests using owner credentials. Meanwhile, 1-click attacks exploited SQL injection through calculated fields in reports. Google has since rectified these vulnerabilities. Organizations should remain vigilant by auditing user access and treating platform connectors as critical. No evidence exists of these flaws being exploited in real-world scenarios. For detailed information, read the full official article at the following link:
Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services
