Experts Reveal ‘LeakyLooker’ Flaws Allow Hackers to Access User Information in Google Looker Studio, So Be on Your Guard



  • Tenable discovers nine Looker Studio flaws called LeakyLooker
  • Bugs allowed cross-tenant SQL injection and credential leaks
  • Google patched all vulnerabilities; Users are encouraged to review access to the report.

Experts have revealed that a series of nine vulnerabilities in Google Looker Studio can be used to execute arbitrary SQL queries against target databases and extract sensitive data from people’s Google Cloud environments.

Tenable security researchers found flaws, called LeakyLooker, that exposed sensitive data in Google Cloud environments, affecting those using virtually any Looker Studio data connector, including Google Sheets, PostgreSQL, MySQL, and others.



Leave a Comment

Your email address will not be published. Required fields are marked *