Experts Reveal ‘LeakyLooker’ Flaw Lets Hackers Access User Information in Google Looker Studio, So Be Vigilant


  • Tenable discloses nine Looker Studio flaws, dubbed LeakyLooker
  • Bugs enabled cross-tenant SQL injection and credential leakage
  • Google has patched all vulnerabilities; users are encouraged to review report access

A series of nine vulnerabilities in Google Looker Studio can be used to run arbitrary SQL queries against target databases and pull sensitive data from people’s Google Cloud environments, experts have revealed.

Security researchers Tenable found the flaws, dubbed LeakyLooker, which exposed sensitive data across Google Cloud environments, affecting those using virtually all Looker Studio data connectors, including Google Sheets, PostgreSQL, MySQL and others.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top