HackMyIP
← Back to News
2026-08-04 Dark Reading

tl;dv AI Notetaker Flaw Lets Hackers Spy on Video Calls

VulnerabilityCloud SecurityPrivacy

A critical misconfiguration in Google Firebase has exposed users of the AI-powered meeting assistant tl;dv to potential surveillance, allowing attackers to query meeting metadata belonging to other users and potentially eavesdrop on sensitive government and corporate video conferences.

Researchers discovered that tl;dv, an AI notetaker that joins meetings to transcribe and summarize conversations, failed to properly secure its backend infrastructure. The Firebase database misconfiguration enabled any authenticated user to send queries that returned meeting information belonging to other organizations, including meeting IDs, participant details, and join links. Security professionals concerned about exposure can verify whether their credentials have appeared in known incidents using the email breach checker on HackMyIP.

The flaw is particularly alarming because tl;dv's bot joins scheduled calls automatically. Once attackers obtained meeting identifiers and metadata through the exposed API, they could potentially join active video conferences undetected. The tool is widely adopted across enterprises and government agencies for its automated transcription and AI-generated summaries, expanding the attack surface considerably. Organizations looking to harden their overall security posture should run a comprehensive privacy checkup to identify other exposed endpoints and configuration drift in their environment.

Cloud misconfigurations remain one of the leading causes of enterprise data exposure, and Firebase in particular has been the source of numerous high-profile leaks. This incident underscores the need for organizations deploying AI-driven SaaS tools to audit third-party vendors' backend configurations and enforce strict least-privilege access controls. tl;dv has since addressed the vulnerability, but affected organizations should review meeting logs for unauthorized participants, rotate any credentials shared during compromised sessions, and monitor for follow-on phishing attempts leveraging harvested meeting data.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

Port Scanner →Security Headers Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

Open ports explained →What is port forwarding? →