A security flaw in the AI meeting assistant tl;dv could have allowed users to access other people's meeting data and, in some cases, join live video calls.
What happened
An AI meeting assistant used by businesses, universities, and government agencies was found to have a security weakness that could allow users to access information about other people's video calls and, in some cases, potentially join them.
The issue involved tl;dv, an AI notetaking service that automatically joins video meetings, records conversations, and generates transcripts and summaries. According to Dark Reading, the problem stemmed from a misconfigured Google Firebase database that failed to properly separate information belonging to different users.
Going deeper
In January 2026, a security researcher known as BobDaHacker discovered that a tl;dv user could access the service's backend Firebase environment and query information from its “meetings” database. While most of tl;dv's data was protected by tenant isolation, meaning users could not normally access another customer's transcripts or recordings, the meetings collection lacked the same protection. This meant an authenticated tl;dv user could query information about meetings taking place across the platform, including meeting times, recording status, and the email address of the meeting creator.
The researcher also found that this information could sometimes be used to gain access to live meetings. In testing, they were reportedly able to join meetings roughly 80% of the time, including meetings involving government agencies and large organizations. One example was a Google Meet session hosted by Malaysia's Ministry of Education.
Dark Reading reported that the researcher found more than 180,000 completed meeting records belonging to more than 80,000 users. The records included meetings associated with government organizations in 23 countries, as well as companies and universities.
What was said
The researcher warned that AI notetakers are receiving significant access to corporate communications without necessarily receiving the same level of security scrutiny as other enterprise software. The researcher told Dark Reading, “The market is growing fast, with very little security scrutiny relative to what these tools have access to.”
They described AI notetakers as a “silent participant with deep access to your communication layer.” The researcher also pointed to a warning sign for users, “If you see an AI notetaker in a call you didn't invite, that's a red flag.”
Dark Reading reported that the researcher attempted to notify tl;dv about the issue but did not receive a response. The publication also said the issue remained live when its report was published on August 4, 2026.
The bigger picture
The incident points out the risks of allowing AI meeting assistants to access sensitive conversations. In healthcare, meetings can contain protected health information (PHI), clinical discussions, and confidential organizational information, meaning a vulnerability could expose data beyond the intended participants.
Furthermore, Google Firebase is not covered under Google Cloud's HIPAA business associate agreement (BAA). Therefore, healthcare organizations should not assume that an application using Firebase is suitable for storing or processing PHI simply because Firebase is part of Google's broader cloud ecosystem.
Healthcare organizations should carefully assess the security and compliance of AI meeting tools before allowing them to access sensitive information. This includes understanding where data is stored, how it is protected, and whether the vendor has appropriate HIPAA agreements in place.
Why it matters
AI productivity tools can create new pathways to sensitive information. A compromised meeting assistant could expose conversations, participants, meeting schedules, and transcripts, potentially revealing confidential discussions.
As AI tools become more common, organizations should ensure they receive the same security scrutiny as other enterprise software.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
What is an AI meeting assistant?
An AI meeting assistant is a tool that can join video calls to record conversations, create transcripts, summarize discussions, and generate meeting notes.
What should organizations do to protect sensitive meetings?
Organizations should vet AI meeting assistants before use, review their security controls and permissions, and ensure sensitive meeting data is appropriately protected.
