When pentesting for a customer, we discovered that fast and deliberate swiping could give us access to very sensitive data through a mobile phone. In this talk Bartek Pszczola will tell the tale of how he discovered a 0-day in a widely used VMware app, what it could lead to and how the process was when reporting the vulnerability to the vendor.