RC RANDOM CHAOS

tl;dv Firestore flaw let any free user read 180K meetings, join live calls

· via Hacker News

Original source

Tl;dv: Over 180k meetings left wide open

Hacker News →

AI meeting-recorder tl;dv, which drops bots into Zoom/Meet/Teams calls for over 2 million users, left its Firestore meetings collection without tenant isolation. Every other collection enforced access control, but this one didn’t — so any authenticated free-tier account could exchange its Firebase token and enumerate the entire platform: 181,874 meeting records spanning 84,312 users across 35,003 domains, each exposing the creator’s email, provider, timestamps, and the joinable conference ID. Because the collection also reveals recording status in real time, roughly 1,000 live calls are queryable at any moment, letting an attacker grab active room IDs and walk into meetings uninvited. The researcher demonstrated this by joining a Malaysian Ministry of Education session with 157 participants and a university startup call mid-screen-share.

The blast radius is severe: government meetings from 23 countries on .gov domains, universities including Berkeley and the University of Tokyo, and corporate customers like HubSpot and Confluent. Beyond metadata, over 1,000 meetings marked public exposed full video, transcripts, and 715 invitee emails. A separate internal World Cup prediction app (built on Base44) had a completely unauthenticated API that leaked tl;dv’s own employee directory — names, corporate emails, and a founder’s personal Gmail — with a single GET request.

The most damning part is the disclosure failure. Reported on January 28, 2026, the bug remained live six months later despite repeated follow-ups; the CTO never responded, contradicting a security page advertising SOC2, GDPR, and EU AI Act compliance plus a promised 24-hour response. The fix is trivial — apply the same Firestore security rules already protecting every other collection — making the neglect, not the vulnerability, the real story.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.