The AI meeting recording application tl;dv, which records, transcribes, and summarizes meetings from Google Meet, Zoom, and Teams, has a significant security flaw. Its Firestore database, projects/lmi-store/databases/(default), lacks proper tenant isolation, allowing any authenticated tl;dv user to access meeting data across all accounts on the platform.
The vulnerability exposes over 181,000 meeting records, including details like the creator's email address, conference ID, provider, recording status, and timestamps. This data includes sensitive content such as sales calls, job interviews, performance reviews, and internal strategy sessions. The issue was reported in January 2026 and remained unaddressed as of July 2026.
For meetings with a 'recording' status, the exposed conference ID corresponds to a live, active call. This allows an unauthorized user to join ongoing meetings. Approximately 1,000 live calls are accessible at any given time, meaning an attacker could potentially join numerous calls simultaneously. The reporter demonstrated this by joining a live Google Meet of the Malaysian Ministry of Education and a university startup team's call.
With over 2 million users, the exposure of meeting recordings and live call access represents a major privacy and security breach. The nature of the exposed content, which often includes confidential discussions and screen-shared sensitive information, highlights the severe implications for individuals and organizations using tl;dv.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The AI meeting recording platform tl;dv has a critical vulnerability in its Firestore database, allowing any authenticated user to access over 181,000 past meeting recordings and join approximately 1,000 live calls without invitation. This exposure of sensitive meeting content, including sales calls, job interviews, and internal strategy sessions, poses a significant privacy and security risk to its over 2 million users.