
The “LeakyLooker” vulnerabilities refer to a set of nine cross-tenant security flaws discovered in Google Looker Studio by Tenable Research. Disclosed on March 10, 2026, these flaws could have allowed attackers to execute arbitrary SQL queries on victims’ databases and exfiltrate sensitive data across different organizations’ Google Cloud Platform (GCP) environments.
Key Details of the Vulnerabilities
The flaws broke fundamental design assumptions in how Looker Studio handles data access, specifically targeting two trust boundaries:
Specific Flaws and Techniques
According to The Hacker News, the vulnerabilities included:
/**/) and ASCII code functions (e.g., CHR(46)) to build restricted project paths.Remediation
Google has remediated all identified issues following Tenable’s responsible disclosure in June 2025. There is currently no evidence that these vulnerabilities were exploited in the wild before they were patched.
#allow #cross-tenant #google #leakylooker” #looker #news #queries #sql #studio #vulnerabilities — News
© Bulletproof Servers. All rights reserved.