2026-08-05 18:35 UTC
The Google Maps Javascript API, often used to embed a map in your site, is vulnerable to a Denial of Wallet attack. You can accrue thousands of dollars in fraudulent charges from Google within hours, often faster than budget alerts can detect and report.
It's being abused by Agents, through Referer header spoofing. This after Google spent a decade telling us that Maps keys are non-sensitive and meant to be public. Their referer and api access security controls can't even prevent this attack.
Replies (0)
No replies.