A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join calls.
August 4, 2026
A popular AI notetaker is allowing hackers to spy on any of its users' conference calls.
Tl;dv (Too Long; Didn't View) is a meeting assistant that automatically joins, records, and transcribes video calls, unless its users specify otherwise. Its website boasts that it's trusted by more than two million users worldwide, including at brand name companies like Salesforce, Forbes, and Cloudflare. In fact, its marketing may be modest. Tl;dv is used across dozens of government agencies, plus large universities and major organizations, across the globe. We know this now because a hacker got into its Google Firebase environment and lurked in some of those customers' calls.
In late January, application security whiz BobDaHacker figured out that with a little gumption, any tl;dv user can access the company's back end Google Firebase environment. And from there, they can access any other users' meeting information. BobDaHacker then used that information to identify and join calls hosted by government agencies and large organizations.








