omi icon indicating copy to clipboard operation
omi copied to clipboard

Google Maps Api keys disclosed in apk/ipa distributed via app stores

Open romamo opened this issue 5 months ago • 0 comments

Describe the bug Google Maps Api keys can be extracted from distributed apk and ipa files

To Reproduce Steps to reproduce the behavior:

  1. Download APK
  2. Extract api key
  3. Use Google Maps for your own tasks, Omi will pay

Current behavior Google Maps Api keys disclosed in apk/ipa distributed via app stores

Expected behavior

  1. Api keys must be placed behind the backend proxy
  2. All requests must be signed

romamo avatar Oct 30 '25 18:10 romamo