One Bad Firebase Rule Exposed Live Meetings

A single missing tenant boundary turned tl;dv from a meeting assistant into a cross-organization listening post. The usual assumption — that each user only sees their own calls — broke for one backend collection, so a signed-in user could reach other customers’ live meetings and their metadata. Dark Reading says the flaw sat in tl;dv’s Google Firebase setup and affected the app’s “meetings” collection, not the rest of the data store. The exposure covered government agencies, universities, and large companies, and the issue was still live at publication. For teams that let an AI bot auto-join meetings, the trust problem sits in the service layer, not the invite link. If that isolation fails, the bot can become an unauthorized attendee across tenants, and the breach reaches every call it can see.

Part of the PlainSec briefing for 2026-08-04

Every edition of this story: One Bad Firebase Rule Exposed Live Meetings

Sources