A Google Firebase misconfiguration in tl;dv, an AI meeting assistant used by more than two million people including staff at Salesforce, Forbes, Cloudflare and various government agencies, let any logged-in user query a shared database containing metadata for every meeting the service had joined. The exposed collection covered 181,874 meetings from 84,312 users across 35,003 domains, including the joinable conference ID for calls that were actively recording — letting anyone watch a live meeting begin and join it uninvited. A security researcher privately reported the flaw to tl;dv starting January 28, 2026, but received no fix after repeated follow-ups, and the exposure was still live when publicly disclosed on August 4, 2026.