“LeakyLooker” Vulnerabilities in Google Looker Studio Allow Cross-Tenant SQL Queries
Mar 10, 2026 // 17:06 - Norina Velotta


The “LeakyLooker” vulnerabilities refer to a set of nine cross-tenant security flaws discovered in Google Looker Studio by Tenable Research. Disclosed on March 10, 2026, these flaws could have allowed attackers to execute arbitrary SQL queries on victims’ databases and exfiltrate sensitive data across different organizations’ Google Cloud Platform (GCP) environments.

Key Details of the Vulnerabilities

The flaws broke fundamental design assumptions in how Looker Studio handles data access, specifically targeting two trust boundaries:

  • 0-Click Exploits (Owner Credentials): These architectural flaws allowed attackers to talk directly to a report’s backend. By sending crafted requests to a public or shared report, attackers could trigger the server to fetch or manipulate data using the owner’s identity without any user interaction.
  • 1-Click Exploits (Viewer Credentials): Attackers could manipulate reports to force a victim to unknowingly execute malicious queries or exfiltrate data they had permission to access when they clicked a malicious link.

Specific Flaws and Techniques

According to The Hacker News, the vulnerabilities included:

  • Zero-Click SQL Injection: Found in database connectors and through stored credentials.
  • Linking API Exploits: Attackers could craft URLs that automatically created temporary reports and executed SQL in a victim’s BigQuery account.
  • Bypassing Mitigations: Researchers bypassed Google’s “no spaces” and “no dots” filters in SQL by using comments (/**/) and ASCII code functions (e.g., CHR(46)) to build restricted project paths.
  • Data Leakage: Vulnerabilities also existed in how the platform handled hyperlinks and image rendering, leading to unauthorized data exposure.

Remediation

Google has remediated all identified issues following Tenable’s responsible disclosure in June 2025. There is currently no evidence that these vulnerabilities were exploited in the wild before they were patched.

#allow  #cross-tenant  #google  #leakylooker”  #looker  #news  #queries  #sql  #studio  #vulnerabilities   —   News