Hasty Briefsbeta

Bilingual

Tl;Dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

6 hours ago
  • tl;dv's Firestore database lacks tenant isolation, allowing any authenticated user to query all meeting records.
  • An attacker can join live meetings uninvited by grabbing conference IDs from the exposed collection.
  • The author demonstrated by joining a Malaysian Ministry of Education meeting and a US university startup call.
  • Over 181,000 meeting records from 84,000 users across 35,000 domains, including government and educational institutions, were exposed.
  • More than 1,000 meetings were public, revealing invitee emails and sensitive content.
  • A subdomain (worldcup.tldv.io) had zero authentication, leaking employee names and emails.
  • The vulnerability was reported in January 2026, but the CTO never responded, and it remained unfixed by July 2026.

Related

Loading…