2 min read
One Guy Spent $266 on AI Models to Root His Own Tablet
Writing Team
:
Aug 26, 2026, 12:00:00 AM
A user with an InfoSec background documented spending $266.15 across four AI models, Claude, Kimi K3, GLM-5.2, and GLM-5.3, to root an Amazon Fire HD tablet that kept shutting itself off, according to his own write-up. Amazon's software held reboot and shutdown permissions on the device and was protected against removal without root access, and no public root method existed for that tablet. Chinese models Kimi K3 and GLM-5.3 found an unpatched, years-old kernel vulnerability and built a working exploit chain. Claude and OpenAI's Codex declined to help, citing cybersecurity safeguards, even when asked to summarize the user's own prior sessions on his own device.
The vulnerability itself, tracked as CVE-2022-38181, is a known, publicly disclosed bug in Arm's Mali GPU driver, fixed by Arm and Amazon years ago, just never patched on this specific tablet's firmware build. Nothing about the underlying flaw was novel. What's notable is that a non-specialist assembled a working exploit chain for it in roughly two days by prompting a chatbot, not by writing code himself.
Ai model access is quietly changing who can do offensive security work
The user calls himself a "prompt kiddie," a nod to the old "script kiddie" label for people who ran exploit tools they didn't understand. The distinction he draws is real: his contribution wasn't technical, it was judgment, knowing when to redirect a model, when to make two models cross-check each other, when to stop. That's a meaningfully lower skill floor for a category of work, device exploitation, that used to require years of specialized training. He notes the same week Anthropic published a math result where a non-mathematician steered Claude to a genuine research advance, credited in the paper as mostly "keep going" and "believe in yourself." The pattern is the same: expertise is shifting from execution to direction.
What the safeguard gap means for the commercial market
The more consequential detail for business audiences is the split in how AI vendors responded. Anthropic's models refused even to discuss the user's own prior work on his own hardware, citing broad cybersecurity safeguards, while Chinese models reasoned through the legality (rooting a device you own falls under a real, current DMCA exemption) and proceeded. That's not a story about which country's AI is "better." It's a signal that safety policy differences between AI vendors are becoming a real competitive and national-security variable, not just a compliance footnote. Companies building products with embedded software locks, kiosk devices, IoT hardware, printers, cars, should assume the population capable of finding and exploiting a forgotten CVE in a shipped product now includes any customer with a laptop and a subscription, not just researchers. That has direct implications for patch management discipline, firmware update cadence, and how liability gets framed when a "protected" device gets opened anyway, and legal teams evaluating that exposure should get advice from counsel rather than a marketing blog.
If your company sells connected hardware or software with usage restrictions, the assumption that obscurity or platform lock-in protects you is getting weaker every quarter. That's a product and trust question as much as a security one, and it's exactly the kind of shift our growth strategy work accounts for when we look at how AI is reshaping customer expectations. If you want help thinking through what AI-accessible technical capability means for your brand's trust story, our AI marketing services team can help.

