AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls

A Serious Security Flaw in AI Notetaker Exposes Government and Corporate Video Calls to Hackers

Imagine attending a high-stakes business meeting or a sensitive government conference call without knowing that a hacker is secretly listening in. This disturbing reality has been made possible by a critical security flaw in tl;dv, an AI-powered meeting assistant used by millions of users worldwide, including some of the world’s most prominent companies and government agencies.

The problem lies in tl;dv’s Google Firebase environment, which allows any user to access the company’s back end system. This vulnerability enables hackers to query any other user’s meeting information and even join live calls with ease. We know this because a security researcher, who wishes to remain anonymous, discovered the issue and demonstrated how it could be exploited.

The tl;dv app is designed to automatically join, record, and transcribe video calls, unless its users specifically opt out of these features. This means that many users are unwittingly exposing themselves and their colleagues to potential hacking risks. The affected organizations include government agencies from over 20 countries, major corporations like Salesforce and Cloudflare, as well as prominent universities such as the University of California at Berkeley.

The security flaw is attributed to a misconfigured Google Firebase environment, which allows any user to query the app’s Cloud Firestore database. While users are isolated within their own “tenants,” the vulnerability lies in the “meetings” collection, where meeting information can be accessed by anyone with a session ID. This means that hackers can view live conference calls, grab metadata, and even join meetings with relative ease.

The researcher, who goes by the handle “BobDaHacker,” discovered this issue after attempting to report it to tl;dv’s developers without success. They then notified Dark Reading, which subsequently tried to reach out to tl;dv through various channels but received no response. The vulnerability remains unfixed as of publication time.

The fix is surprisingly simple: implementing a few lines of security rules that scope reads to the authenticated user’s organization would be enough to lock down the Firestore database and prevent this type of exploitation. It’s a stark reminder that even with advanced technologies like AI-powered meeting assistants, security vulnerabilities can still arise from seemingly innocuous configurations.

For users of tl;dv, this vulnerability serves as a wake-up call to review their security settings and ensure they are not inadvertently exposing themselves or others to hacking risks. As for the affected organizations, it’s essential that they take immediate action to address this issue and prevent further exploitation. In an era where remote work is increasingly prevalent, protecting sensitive information and maintaining confidentiality has never been more crucial.


Source: Dark Reading — 2026-08-04