tl;dv (Too Long; Didn't View), an AI-powered meeting recording platform used by over 2 million people, has a critical security vulnerability that exposes 180,000 conferences and allows unauthorized access to live calls. The flaw affects the service's integration with Google Meet, Microsoft Teams, and Zoom.
The vulnerability stems from inadequate access controls in the platform's Firestore database. Any authenticated user can query meetings across the entire platform, not just their own. This means anyone with a tl;dv account—even a free one—can potentially view conference recordings and metadata belonging to other users and organizations.
Exposed data includes government meetings from 23 countries, among them a Brazilian government meeting related to the Atlantic Forest Pact (PACTO Mata Atlântica). The breach affects sensitive communications at scale, raising concerns about data privacy and compliance violations. Security researcher BobDaHacker reported the vulnerability in January, but it remains unfixed months later.

