AUTO-UPDATED

Over 181,000 AI meeting recordings left wide open in note taking app

A critical security vulnerability in the AI meeting platform tl;dv has left the private meeting data of over 84,000 users exposed in an unsecured Firestore database for months.

Key Points

  • The vulnerability allows any authenticated user to query the entire "meetings" collection, exposing email addresses, conference IDs, and real-time recording statuses.
  • Researchers confirmed the flaw by joining live, uninvited meetings hosted by government entities and universities, including the Malaysian Ministry of Education.
  • Data from 35,003 unique domains is affected, including sensitive records from government agencies across 23 countries and major corporations like HubSpot.
  • An additional internal application, "World Cup Pick'em," lacks authentication, leaking the full names and corporate email addresses of tl;dv employees.
  • Despite multiple disclosures beginning in January 2026, the company has failed to secure the database or respond to security inquiries as of July 2026.

Why it Matters

This incident highlights a severe failure in data privacy and tenant isolation for a platform that records sensitive corporate, government, and academic communications. The lack of remediation despite repeated warnings raises significant concerns regarding the company's commitment to its stated SOC2 and GDPR compliance standards.
Bobdahacker.com Published by BobDaHacker
Read original