Tl;Dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
6 hours ago
- tl;dv's Firestore database lacks tenant isolation, allowing any authenticated user to query all meeting records.
- An attacker can join live meetings uninvited by grabbing conference IDs from the exposed collection.
- The author demonstrated by joining a Malaysian Ministry of Education meeting and a US university startup call.
- Over 181,000 meeting records from 84,000 users across 35,000 domains, including government and educational institutions, were exposed.
- More than 1,000 meetings were public, revealing invitee emails and sensitive content.
- A subdomain (worldcup.tldv.io) had zero authentication, leaking employee names and emails.
- The vulnerability was reported in January 2026, but the CTO never responded, and it remained unfixed by July 2026.