A vulnerability in the AI meeting assistant tl;dv, caused by a misconfigured Google Firebase backend, allows any user to access other users' meeting metadata and potentially join live government and corporate video calls. Security researcher BobDaHacker found that missing isolation in the app's “meetings” data exposed records from over 80,000 users, including sensitive calls from multiple countries and large organizations, with some meetings left publicly accessible. The incident highlights security risks in AI notetakers, which have deep access to communications and often lack sufficient scrutiny or proper privacy configurations.
https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls

