- What: A misconfigured Google Firebase app allows hackers to spy on video calls.
- Impact: Users' meeting data and calls could be accessed by unauthorized parties.
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources APPLICATION SECURITY CYBERATTACKS & DATA BREACHES CYBER RISK СLOUD SECURITY NEWS AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join calls. Nate Nelson,Contributing Writer August 4, 2026 5 Min Read SOURCE: JACK191 VIA GETTY IMAGES A popular AI notetaker is allowing hackers to spy on any of its users' conference calls. Tl;dv (Too Long; Didn't View) is a meeting assistant that automatically joins, records, and transcribes video calls, unless its users specify otherwise. Its website boasts that it's trusted by more than two million users worldwide, including at brand name companies like Salesforce, Forbes, and Cloudflare. In fact, its marketing may be modest. Tl;dv is used across dozens of government agencies, plus large universities and major organizations, across the globe. We know this now because a hacker got into its Google Firebase environment and lurked in some of those customers' calls. LOADING... In late January, application security whiz BobDaHacker figured out that with a little gumption, any tl;dv user can access the company's back end Google Firebase environment. And from there, they can access any other users' meeting information. BobDaHacker then used that information to identify and join calls hosted by government agencies and large organizations. Related:AI Harnesses Burst With Potential Exploit Opps After trying to report the issue to no avail, they notified Dark Reading about the issue. Dark Reading then tried reaching tl;dv through its press and marketing contacts, but received no reply. The issue is still live as of the time of publication. Vulnerabilities in the tl;dv Meeting Assistant When a user signs up for or signs into tl;dv, they're assigned a session ID in the app's back end Firebase system. This session ID affords them unusual power, though, to query the app's Cloud Firestore database. LOADING... It would be one thing if the user could only see the Firestore data associated with their account. Indeed, that's almost entirely the case. Users cannot see other users' transcripts, recordings, chats, etc., thanks to basic tenant isolation. The app has an Achilles' heel, though: its "meetings" collection. Thanks to missing isolation for that one container, any tl;dv user can query every live conference call in the world into which tl;dv is invited. They can also grab some light metadata — like meeting timestamps and recording status — as well as its creator's email address. When developers build apps with Firebase, "Firestore security rules are the first thing Google tells you to configure," BobDaHacker tells Dark Reading. "The documentation walks you through it with examples. The default rules when you create a new Firestore database even warn you that they're open and need to be locked down." The fix would be just as effortless to implement. "A few lines of security rules that scope reads to the authenticated user's organization," they say. Related:OpenAI's Rogue Model Claims More Victims Beyond Hugging Face Major Government, Corporate Conference Calls Exposed Obtaining meeting information doesn't itself grant access to the meeting. Yet in their testing, BobDaHacker found a way into most tl;dv users' meetings, most of the time. Some, such as a large Google Meet call hosted by the Malaysian Ministry of Education's primary management training institute, were left open to the public. For private calls, BobDaHacker says, impersonating an AI notetaker like tl;dv and then requesting to join the meeting typically did the trick. They tell Dark Reading that they were allowed into meetings roughly 80% of the time. When they weren't actively joining live calls, BobDaHacker was delving deeper into the app's back end. There, they found more than 180,000 completed call records belonging to more than 80,000 users. These records documented meetings which, judging by the .gov domains exposed, were convened by governments of 23 different countries. They also included meetings hosted by large corporations — like HubSpot and Japan's largest real estate developer, Mitsui Fudosan — and internationally acclaimed universities such as the University of California at Berkeley, the University of Tokyo, and others. Related:When AppSec Scanners Become a Supply Chain Attack Vector In a minority of cases, meeting IDs led to further data leakage. BobDaHacker took a sample of more than 27,000 meeting IDs, scraped them for publicly exposed data, and found that more than 1,000 left invitees' emails and call transcripts on the open Internet. Among them were a meeting at Ukraine's Ministry of Digital Transformation, and a meeting between the state government in São Paulo, Brazil and various conservation groups. The Risk in AI Notetakers Have you ever been on a conference call and half the participants are AI notetakers? Notetakers from people on the call, notetakers in place of people who couldn't make the call, notetakers people forgot they still have running — they all seem to pop up these days. Few users give much thought to their AI notetakers, or especially anyone else's, even though they're near-ubiquitous and often wield high-level permissions. Most notetakers join and scribe all of a user's meetings by default, unless users specify otherwise. They require access to video and audio, and, usually, related apps like calendars, contacts, etc. BobDaHacker warns that "the market is growing fast, with very little security scrutiny relative to what these tools have access to. Most people treat them like browser extensions they installed and forgot about. They're a silent participant with deep access to your communication layer." To limit the risk in running AI notetakers, they suggest two areas of focus. First, "Be aware that the bot is a participant. If you see an AI notetaker in a call you didn't invite, that's a red flag. In the Malaysian government meeting I joined, the tl;dv bot was right there in the participant list. 157 people saw it and nobody questioned it." Most importantly, users should always configure their meeting privacy settings proportionate to the sensitivity of those meetings' content and participants. "Out of roughly 70,000 meetings I checked through the REST API, only about 1,000 had public sharing enabled. Those users had their transcripts and invitee emails exposed. The other 69,000 were protected from content exposure by their privacy settings alone. Default to private," they say. Internal Company Game Leaks Employee Data Besides leaking users' meeting data, tl;dv is also leaking its own employees' names and email addresses, through rather less conventional means. While exploring the company's subdomains, BobDaHacker came across an internal and possibly vibecoded World Cup bracket game called "Too Long; Didn't Score." TL;DS's application programming interface (API) endpoint for player data has no authentication, and a simple GET request yields all 42 employees who played. Just shy of half of those employees signed up with their guessable work emails, but the rest have unintentionally leaked their personal email addresses. Other leaked data includes chosen usernames — some creative, like "ChocoLoco" and "Super Duper CEO" — and the identity of the game's admin, the company's in-house blogger. The game remains live, weeks after the World Cup concluded. About the Author Nate Nelson Contributing Writer Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media. He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify. He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI More Webinars You May Also Like APPLICATION SECURITY Supply Chain Attack Secretly Installs OpenClaw for Cline Users by Rob Wright FEB 19, 2026 APPLICATION SECURITY Chinese Hackers Hijack Notepad++ Updates for 6 Months by Jai Vijayan FEB 02, 2026 APPLICATION SECURITY Trump Administration Rescinds Biden-Era Software Guidance by Alexander Culafi JAN 29, 2026 APPLICATION SECURITY Microsoft Fixes Exploited Zero Day in Light Patch Tuesday by Jai Vijayan DEC 09, 2025 Black Hat USA Coverage APPLICATION SECURITY AI Harnesses Burst With Potential Exploit Opps byRobert Lemos JUL 30, 2026 4 MIN READ APPLICATION SECURITY When AppSec Scanners Become a Supply Chain Attack Vector byEricka Chickowski JUL 29, 2026 5 MIN READ CYBERSECURITY OPERATIONS Red Agents vs. Blue Age