tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
Six months after reporting a security vulnerability to tl;dv, an AI meeting recording platform, no response or resolution had been provided by the company. tl;dv drops a bot into any Google Meet, Zoom, or Teams call, records, transcribes, and generates summaries of the conversation. Over 2 million users trust the platform with their sensitive sales calls, job interviews, performance reviews, and internal strategy sessions.
The platform stores all this content, including government meetings from 23 countries, university sessions from major institutions, and corporate meetings from various domains. Despite the potential risks, tl;dv failed to implement server-side validation, leaving over 181,874 meetings with no tenant isolation. This means any authenticated user could query and view every meeting, including live calls, across all accounts on the platform.
The vulnerability was demonstrated by joining a live call with over 157 participants, including the Malaysian Ministry of Education. The platform's Firestore database was left wide open, with no tenant isolation, allowing unauthorized access to every meeting record.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.