SureCloud's Senior Security Consultant will be discussing a critical disclosure discovered on the children's VTech Storio Max tablet, which allowed attackers full access to the device. Elliott found a vulnerable service enabled on the tablet that could be exploited by a script placed on the website, triggered when Storio Max users visited the page. The code granted attackers full root control over the targeted device, including access to the webcam, speakers and microphone. The disclosure was reported to VTech, and a patch fixing the vulnerability was released within 30 days. The vulnerability was granted a CVE, and the story was featured on the BBC.Learning Outcomes:Gain a better understanding on how to approach unusual devices from a methodology standpointIdentify how manufacturers can break a secure base (Android phone with Vtech software)Triaging of the custom parts of devicesLearn how accessible ARM assembly can beSee a live demonstration showing the impact of proof on concept and how writing an exploit code made the manufacturer resolve the issue quickly. Elliot comments: “It’s always better to show than merely tell.”