Dark Reading
Read post

AI Notetaker Exposes Government, Corporate Video Calls

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A security researcher known as BobDaHacker discovered a critical Firebase misconfiguration in tl;dv, a popular AI meeting notetaker used by over two million users. The flaw allows any authenticated tl;dv user to query the app's Cloud Firestore 'meetings' collection, exposing live and completed call metadata — including creator email addresses — for all meetings globally. The researcher was able to join calls hosted by government agencies from 23 countries, major corporations, and universities roughly 80% of the time by impersonating an AI notetaker bot. Over 180,000 completed call records and more than 1,000 meetings with publicly exposed transcripts and invitee emails were found. A separate unauthenticated API endpoint in an internal company game also leaked employee personal email addresses. The vulnerability remains unpatched as of publication, and tl;dv has not responded to disclosure attempts.

    #firebase#appsec
Aug 04•6m read time•From darkreading.com
Post cover image
Table of contents
Vulnerabilities in the tl;dv Meeting AssistantMajor Government, Corporate Conference Calls ExposedThe Risk in AI NotetakersInternal Company Game Leaks Employee Data
55 Impressions
Dark Reading's image
Dark Reading

DR (DZone Research) offers insights into software development trends, industry surveys, and technolo...

2.2K Followers

•

745 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard