AI Notetaker Exposes Government, Corporate Video Calls
The AI meeting recording platform tl;dv has a critical security vulnerability in its Firestore database configuration, allowing any authenticated user to access all meeting metadata across all accounts without tenant isolation. This flaw exposes live conference IDs, enabling unauthorized joining of active government, corporate, and university video calls. Despite responsible disclosure in January 2026, the vulnerability remained unpatched as of July 2026. Additionally, an internal employee directory is publicly accessible via an unauthenticated API. The platform stores sensitive meeting content including government briefings and corporate discussions, putting user privacy and confidentiality at significant risk.
AI Analysis
Technical Summary
tl;dv, an AI meeting recording service integrated with Google Meet, Zoom, and Teams, uses a Firestore database to store meeting metadata. Due to missing tenant isolation in the 'meetings' collection, any authenticated user can query and retrieve all meetings across all accounts, including live conference IDs that allow joining active calls uninvited. The vulnerability was discovered and responsibly disclosed in January 2026 but remained unaddressed six months later. The exposed data includes creator emails, conference IDs, recording status, and timestamps for over 181,000 meetings from more than 84,000 users across 35,000 domains, including government and educational institutions worldwide. Furthermore, an internal employee directory API is accessible without authentication, exposing employee names and emails. The vendor has not responded to multiple disclosures and has not remediated the issue.
Potential Impact
This vulnerability allows unauthorized access to sensitive meeting metadata and live conference sessions, compromising the confidentiality of government, corporate, and academic video calls. Attackers can join live meetings uninvited, potentially eavesdropping on confidential discussions and accessing sensitive information. The exposure of internal employee data via an unauthenticated API further increases the risk of targeted attacks such as phishing or social engineering. The lack of tenant isolation in the database significantly undermines user privacy and trust in the platform.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor must implement Firestore security rules to enforce tenant isolation on the 'meetings' collection, restricting access to only authorized users. Additionally, the unauthenticated internal API endpoints should be secured or disabled. Users and organizations relying on tl;dv should be cautious about sensitive content shared on the platform until the issue is resolved. Continued follow-up with the vendor is recommended to ensure remediation.
AI Notetaker Exposes Government, Corporate Video Calls
Description
The AI meeting recording platform tl;dv has a critical security vulnerability in its Firestore database configuration, allowing any authenticated user to access all meeting metadata across all accounts without tenant isolation. This flaw exposes live conference IDs, enabling unauthorized joining of active government, corporate, and university video calls. Despite responsible disclosure in January 2026, the vulnerability remained unpatched as of July 2026. Additionally, an internal employee directory is publicly accessible via an unauthenticated API. The platform stores sensitive meeting content including government briefings and corporate discussions, putting user privacy and confidentiality at significant risk.
Reddit Discussion
In late January, application security whiz BobDaHacker figured out that with a little gumption, any tl;dv user can access the company's back end Google Firebase environment. And from there, they can access any other users' meeting information. BobDaHacker then used that information to identify and join calls hosted by government agencies and large organizations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
tl;dv, an AI meeting recording service integrated with Google Meet, Zoom, and Teams, uses a Firestore database to store meeting metadata. Due to missing tenant isolation in the 'meetings' collection, any authenticated user can query and retrieve all meetings across all accounts, including live conference IDs that allow joining active calls uninvited. The vulnerability was discovered and responsibly disclosed in January 2026 but remained unaddressed six months later. The exposed data includes creator emails, conference IDs, recording status, and timestamps for over 181,000 meetings from more than 84,000 users across 35,000 domains, including government and educational institutions worldwide. Furthermore, an internal employee directory API is accessible without authentication, exposing employee names and emails. The vendor has not responded to multiple disclosures and has not remediated the issue.
Potential Impact
This vulnerability allows unauthorized access to sensitive meeting metadata and live conference sessions, compromising the confidentiality of government, corporate, and academic video calls. Attackers can join live meetings uninvited, potentially eavesdropping on confidential discussions and accessing sensitive information. The exposure of internal employee data via an unauthenticated API further increases the risk of targeted attacks such as phishing or social engineering. The lack of tenant isolation in the database significantly undermines user privacy and trust in the platform.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor must implement Firestore security rules to enforce tenant isolation on the 'meetings' collection, restricting access to only authorized users. Additionally, the unauthenticated internal API endpoints should be secured or disabled. Users and organizations relying on tl;dv should be cautious about sensitive content shared on the platform until the issue is resolved. Continued follow-up with the vendor is recommended to ensure remediation.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a782f10bf8831d5393c98a4
Added to database: 08/09/2026, 07:41:04 UTC
Last enriched: 08/09/2026, 07:41:15 UTC
Last updated: 08/09/2026, 08:40:59 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.