- Sources: researcher write-up, discussion
- Summary: tl;dv is a hosted AI meeting recorder that joins Google Meet, Zoom, and Teams calls, so no affected version applies and the reported exposure covers the platform's tenants as the researcher describes them. A researcher publishing as BobDaHacker, in a post bylined 2026-08-04, states the meetings collection in the product's Firestore database carries no tenant isolation, so any authenticated free-tier account can enumerate every meeting on the platform. The post reports 181,874 meeting records across 84,312 users and 35,003 email domains, including government domains from 23 countries and university domains, and states that roughly 1,000 records at a time carry a joinable conference ID for a call in progress. The researcher states he joined two live calls he was not invited to. He also reports a separate internal World Cup app with an unauthenticated entity API returning 19 employee records. The disclosure timeline runs from 2026-01-28 through July 2026 with no response from the vendor's CTO. No vendor statement and no independent reproduction exist, and the post's body and timeline table place the researcher's last stated verification in July 2026 rather than August, so the technical claims are attributed to him and the story is carried as developing.
- Why it matters: The exposed records cover sales calls, job interviews, and performance reviews, so an organization using tl;dv should treat meeting metadata and live conference IDs as exposed until the vendor states otherwise.
- Follow-up: Track whether tl;dv issues a statement, whether the tenant isolation gap is independently reproduced, and whether the exposure is confirmed open after July 2026.
send feedback on this story