Critical security vulnerability in tl;dv (AI meeting summary service): JWT tokens were convertible to unrestricted Firebase tokens, allowing any user to query the entire Firestore database and access other customers' meeting videos, including live sessions. Researcher reported flaw on Jan 28 but tl;dv has not responded; proof-of-concept shown accessing Malaysian Ministry of Education meeting. This poses severe data breach risk for all enterprise users.
← Back to all articles