Exploits

LeakyLooker: 9 Critical Flaws in Google Looker Studio Fixed

Published  ·  3 min read

Google Looker Studio, formerly Data Studio is a go-to tool for turning data from BigQuery, Sheets, Spanner, Cloud Storage, and dozens of other sources into clean, shareable dashboards. But in mid-2025, Tenable Research uncovered a set of nine serious cross-tenant vulnerabilities that could have turned that convenience into a serious risk.

Collectively dubbed LeakyLooker, these flaws broke some core assumptions about isolation in multi-tenant environments. An attacker could potentially run arbitrary SQL queries on a victim's databases, exfiltrate sensitive data, modify or delete records, and even pivot across Google Cloud projects, all without needing credentials in many cases.

Tenable's Liv Matan described it bluntly: the issues shattered the promise that a "Viewer" role should only see data, not control it. Exploitation paths ranged from zero-click attacks (no user interaction required) to one-click scenarios where simply opening or sharing a crafted report could trigger malicious behavior.

Key issues included:
1. Zero-click SQL injection on database connectors and stored credentials
2. Injection via native functions, custom queries, or the Linking API in BigQuery/Spanner
3. Data source leaks through hyperlinks or image rendering
4. XS-Leak techniques using frame counting and timing oracles
5. Even a denial-of-wallet attack that could rack up BigQuery costs for victims

In one scenario, attackers could scan for public (or improperly shared private) Looker Studio reports connected to BigQuery, then hijack the underlying project to query entire datasets. Another involved cloning reports while retaining the original owner's credentials via a logic flaw in the copy feature, leading to table modifications or deletions in JDBC-connected sources like PostgreSQL or MySQL.

A particularly sneaky one-click path: share a malicious report that forces the victim's browser to execute code contacting an attacker-controlled project, reconstructing databases from access logs.

Google received responsible disclosure from Tenable in June 2025 and patched everything before public release. No proof has been found that these had been used actively in the wild, which is great considering the possible damage that could have been done. Any company who uses Looker Studio with confidential GCP information (i.e. financial services, health care, and any other industry that is regulated) is potentially at risk. 

The solutions are now online, so please make sure to do the following before using Looker Studio with your team:
1. Double check that your reports do not have overly permissive settings (e.g. public sharing or allowing too many people to see them)
2. Check your connected data sources for any confidential information that may have been exposed. 
3. Stay on top of Google's updates, Looker Studio evolves quickly

This batch of bugs highlights how tricky cross-tenant isolation can be in cloud BI tools. When features like report sharing and credential pass through meet creative chaining, the results can be eye-opening. Good on Google for the swift remediation, and props to Tenable for the deep dive, better discovered in a lab than in the wild. If Looker Studio is part of your stack, a quick audit of shared reports wouldn't hurt.

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067