Google eliminates the security risk of unrestricted API keys in Gemini through a phased migration to authentication keys with granular access control by September 2026.
A missing authorization check in backend APIs allowed unauthorized users to access critical streaming and match data systems for the 2026 World Cup through FIFA’s public agents portal.