GCP-2026-043
Cybersecurity Classified by Officially
Published: 2026-06-24
Description
Description Severity NotesA vulnerability was found in Firebase Studio where the
GetSignedGcsUrl RPC allowed authenticated users to list
buckets and download deployment source code of other tenants.
No action is required to mitigate this vulnerability as the fix has been deployed to the backend service.
As a precautionary measure, users who stored sensitive information,
such as API keys (for example, GEMINI_API_KEY), within
their Firebase Studio workspace may choose to rotate these keys. For
instructions, see the
Firebase Studio troubleshooting guide.
This is an extract. The publication continues at the source.
Read the original at the source: https://docs.cloud.google.com/support/bulletins/index#gcp-2026-043
Officially imported this from Google’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
4 versions recorded. The original is kept in full — nothing is overwritten.
- v4 imported change on current
- v3 imported change on
- v2 imported change on
- v1 as first published on
Provenance
- Organization
- Google — imported from official source
- Official source
- https://cloud.google.com/feeds/google-cloud-security-bulletins.xml RSS
- Imported
- September 15, 2026 20:57
- Versions
- 4 recorded
- Identity
tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-043