AI Notetaker Exposes Government, Corporate Video Calls
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A security researcher known as BobDaHacker discovered a critical Firebase misconfiguration in tl;dv, a popular AI meeting notetaker used by over two million users. The flaw allows any authenticated tl;dv user to query the app's Cloud Firestore 'meetings' collection, exposing live and completed call metadata — including creator email addresses — for all meetings globally. The researcher was able to join calls hosted by government agencies from 23 countries, major corporations, and universities roughly 80% of the time by impersonating an AI notetaker bot. Over 180,000 completed call records and more than 1,000 meetings with publicly exposed transcripts and invitee emails were found. A separate unauthenticated API endpoint in an internal company game also leaked employee personal email addresses. The vulnerability remains unpatched as of publication, and tl;dv has not responded to disclosure attempts.