Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI ...
A high-severity Chrome vulnerability has allowed malicious extensions to exploit the Gemini panel and gain elevated access to camera, microphone, and files.