Enterprise

tl;dv Left 181,874 Meetings Open in Firestore for Six Months After Disclosure

A missing tenant-isolation rule exposed live calls at government agencies, HubSpot, Confluent, and major universities. The AI notetaker's CTO didn't respond until Dark Reading did.

Photo: Unsplash / Chris Montgomery — Laptop screen showing a grid of participants on a video conference call

For six months, any authenticated tl;dv user could query 181,874 meetings belonging to 84,312 other users across 35,003 domains, thanks to a missing tenant-isolation rule in the AI notetaker’s Firestore database. The flaw wasn’t exotic. It was a Google cloud database configured to let every logged-in tenant read every other tenant’s data, which is what happens when you ship a multi-tenant SaaS product without writing the security rules that make it multi-tenant.

The researcher who disclosed it, pseudonymous as BobDaHacker, described the fix as “a few lines of security rules that scope reads to the authenticated user’s organization.” That’s the whole patch. Six months of exposure, resolved by a config diff.

tl;dv’s product injects a bot into Google Meet, Zoom, and Microsoft Teams to transcribe calls. The company claims more than two million users and lists Salesforce, Forbes, and Cloudflare as customers on its site. The exposed collection reached considerably further: live calls at HubSpot, Confluent, Mitsui-Soko, and AnyMind Group; academic sessions at UC Berkeley, the University of Tokyo, and Universidad Nacional de Colombia; and government meetings from 23 countries. Roughly 1,000 meetings carried a recording status at any given moment.

Metadata was only the beginning. In testing, BobDaHacker joined live meetings roughly 80% of the time by impersonating an AI notetaker, including a Malaysian Ministry of Education training session with 157 participants who never noticed the extra attendee.

Disclosure went to tl;dv on January 28, 2026. Through July, the database remained wide open and the CTO didn’t reply. The patch shipped only after Dark Reading published its investigation in August.

tl;dv’s response is worth reading as a specimen of narrative management. The company said access required “specific programmatic actions by a technically versed hacker” and that the affected content had been “intentionally set to public by users.” Its CTO conceded he “should have kept the researcher updated after his initial outreach earlier this year.”

eSecurity Planet has flagged inadequate tenant isolation in AI-transcription backends as a recurring failure mode across the category, and the Identity Theft Resource Center logged 1,803 data compromises in the first half of 2026, on pace to surpass last year’s record of 3,321. The bot in the meeting is the smallest of the exposures. The database behind it’s the story.

Sources