tl;dv AI Meeting Recordings Exposed by Database Flaw
TL;DR. An AI meeting recording platform, tl;dv, exposed over 181,000 meeting records from 84,312 users due to an unsecured Firestore database. - The vulnerability allowed any authenticated tl;dv user to access conference IDs for live and recorded calls. - This flaw enabled unauthorized access to sensitive meetings, including government and university sessions. - The security issue persisted for six months despite multiple disclosure attempts to the company.
- tl;dv, an AI meeting recording platform, suffered a critical data exposure.
- A missing Firestore security rule allowed unauthorized access to 181,874 meeting records.
- The vulnerability exposed live conference IDs, enabling uninvited entry into active calls.
- Affected data included sensitive discussions from government bodies and educational institutions.
- The flaw remained unpatched for six months despite the reporter's repeated notifications.
- The exposed data included creator emails, conference IDs, and recording statuses.
Sources
- Over 181,000 AI meeting recordings left wide open in note taking app — bobdahacker.com