TechNewsReel
Live

Firebase Flaw Exposed 180,000 AI Notetaker Meeting Records

A critical security misconfiguration in tl;dv's Cloud Firestore database allowed a researcher to join private calls and access global meeting metadata.

TechNewsReel Newsroom · August 4, 2026

A critical security misconfiguration in the Google Firebase environment of AI meeting assistant tl;dv has exposed the private communications of thousands of users worldwide. The flaw allowed unauthorized parties to identify live conference calls and access sensitive meeting metadata, creating a significant privacy breach for corporate and government entities.

According to a report from Dark Reading, the vulnerability stemmed from a lack of isolation within the 'meetings' collection of tl;dv's Cloud Firestore database. This error enabled any authenticated user to query all live calls. A security researcher known as BobDaHacker exploited this gap to uncover records of more than 180,000 completed calls belonging to over 80,000 users across 23 countries. By impersonating the AI bot or identifying calls left open to the public, the researcher successfully joined live meetings approximately 80% of the time.

Among the exposed organizations were high-profile entities including the Malaysian Ministry of Education, Ukraine's Ministry of Digital Transformation, HubSpot, Mitsui Fudosan, UC Berkeley, and the University of Tokyo. Additionally, the researcher discovered a separate leak involving an internal company game titled 'Too Long; Didn't Score,' which exposed the names and both professional and personal email addresses of 42 tl;dv employees via an unauthenticated API endpoint.

The Risk of Silent Participants

AI notetakers have become ubiquitous in professional settings, often joining calls by default with high-level permissions to record audio and video. Because these tools are frequently viewed as passive browser extensions, users rarely scrutinize their security architecture. BobDaHacker noted that the market is expanding rapidly with very little security scrutiny relative to the level of access these tools possess, describing them as "a silent participant with deep access to your communication layer."

Industry Implications

This incident underscores a systemic risk where AI tools are granted deep access to sensitive communications without sufficient security controls. The breach demonstrates how a simple error in cloud configuration—specifically Firestore security rules—can lead to massive intelligence leaks on a global scale. BobDaHacker suggested that the fix is straightforward, requiring only a few lines of security rules to scope reads to the authenticated user's specific organization.

Current Status

Dark Reading reported that the issue remained live at the time of their publication. The outlet stated that they attempted to contact tl;dv through both press and marketing channels but received no response. It remains to be seen if the company has since patched the Firestore isolation flaw or the unauthenticated API endpoint that leaked employee data.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.