Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

AI Notetaker Exposes Government, Corporate Video Calls

0
Medium
Vulnerabilitycybersecurityreddit
Published: 08/09/2026 (08/09/2026, 07:00:32 UTC)
Source: Reddit Cybersecurity

Description

The AI meeting recording platform tl;dv has a critical security vulnerability in its Firestore database configuration, allowing any authenticated user to access all meeting metadata across all accounts without tenant isolation. This flaw exposes live conference IDs, enabling unauthorized joining of active government, corporate, and university video calls. Despite responsible disclosure in January 2026, the vulnerability remained unpatched as of July 2026. Additionally, an internal employee directory is publicly accessible via an unauthenticated API. The platform stores sensitive meeting content including government briefings and corporate discussions, putting user privacy and confidentiality at significant risk.

Reddit Discussion

r/cybersecurity·posted by u/kochurshak
00

In late January, application security whiz BobDaHacker figured out that with a little gumption, any tl;dv user can access the company's back end Google Firebase environment. And from there, they can access any other users' meeting information. BobDaHacker then used that information to identify and join calls hosted by government agencies and large organizations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/09/2026, 07:41:15 UTC

Technical Analysis

tl;dv, an AI meeting recording service integrated with Google Meet, Zoom, and Teams, uses a Firestore database to store meeting metadata. Due to missing tenant isolation in the 'meetings' collection, any authenticated user can query and retrieve all meetings across all accounts, including live conference IDs that allow joining active calls uninvited. The vulnerability was discovered and responsibly disclosed in January 2026 but remained unaddressed six months later. The exposed data includes creator emails, conference IDs, recording status, and timestamps for over 181,000 meetings from more than 84,000 users across 35,000 domains, including government and educational institutions worldwide. Furthermore, an internal employee directory API is accessible without authentication, exposing employee names and emails. The vendor has not responded to multiple disclosures and has not remediated the issue.

Potential Impact

This vulnerability allows unauthorized access to sensitive meeting metadata and live conference sessions, compromising the confidentiality of government, corporate, and academic video calls. Attackers can join live meetings uninvited, potentially eavesdropping on confidential discussions and accessing sensitive information. The exposure of internal employee data via an unauthenticated API further increases the risk of targeted attacks such as phishing or social engineering. The lack of tenant isolation in the database significantly undermines user privacy and trust in the platform.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor must implement Firestore security rules to enforce tenant isolation on the 'meetings' collection, restricting access to only authorized users. Additionally, the unauthenticated internal API endpoints should be secured or disabled. Users and organizations relying on tl;dv should be cautious about sensitive content shared on the platform until the issue is resolved. Continued follow-up with the vendor is recommended to ensure remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a782f10bf8831d5393c98a4

Added to database: 08/09/2026, 07:41:04 UTC

Last enriched: 08/09/2026, 07:41:15 UTC

Last updated: 08/09/2026, 08:40:59 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses