tl;dv AI meeting note-taker leaks 181,874 recordings including live Google Meet calls, ignored for 6 months
- tl;dv, an AI meeting note-taking bot used on Google Meet, Zoom, and Teams with over 2 million users, has a Firestore database with no tenant isolation, letting any authenticated free-tier user query every meeting record on the platform.
- The exposed meetings collection reveals creator emails, joinable conference IDs, provider, and recording status for 181,874 meetings across 84,312 unique users and 35,003 email domains, including government agencies in 23 countries and universities like Berkeley and the University of Tokyo.
- At any given time roughly 1,000 meetings show status recording, meaning their Google Meet or Teams IDs are live and joinable by an attacker who scrapes the database in real time.
- The researcher joined two live calls to prove the exploit, including a Malaysian Ministry of Education presentation with 157 participants and a US university student startup meeting with 21 people, entering both uninvited via leaked conference IDs.
- The vulnerability was reported to tl;dv's CEO and CTO on January 28, 2026; as of the August 2026 writeup the Firestore database is still open and neither executive has fixed it or responded.
Hacker News opinions
Six months to patch a cross-tenant Firestore leak like this is insane. If I left something that critical open for 6 hours there'd be hell to pay.
Yeah and in this case the CEO knew about it and just did nothing for months.
Cross-tenant isolation is one of the most basic things to check. I'm shocked how often it just isn't there.
This keeps happening with Firebase. It's not the platform's fault exactly, but there's clearly a skill gap around securing it. Wasn't there a dating app with the same kind of leak this year?
Firebase markets itself as easy to use, and that ease is exactly why people skip the security part and move on to the next feature. If this happens again and again it's a choice, not an accident.
I get wanting to shame the platform, but why name a huge list of their government and university clients in the writeup? That exposes them too.
He's spent six months trying to get tldv to fix it through private channels. Public shame is often the only lever left when a company won't act.
Did he even try ? Maybe someone on that team would've actually read a short email.
He emailed the CEO directly and the CTO too, repeatedly, over six months, and got nothing. The privacy inbox line was buried at the bottom of their own policy.
Does Ukraine know Russia might be watching their Ministry of Digital Transformation's meetings through this hole?
I run a deepfake voice phishing company and this is exactly the kind of leaked audio attackers want. Buyers always ask where attackers would even get voice samples of employees, and this is the answer.
I'm into AI note takers but there's no way I'll expose my clients to this. I've tried local-only tools like meetily but reliable diarization and speaker ID are still the real bottleneck, not the transcription itself.
Doesn't matter if you personally avoid these tools. If even one person on the call uses one, your voice and words are already being recorded and stored somewhere you don't control.