A newly disclosed Gemini Live API issue highlights a familiar security trap in AI apps: if short-lived credentials are not tightly scoped, a real-time feature can inherit far more trust than its designers intended.