Kids’ Tablet Security Flaw: Preloaded Malware Exposes Children’s Data
Security Researcher Uncovers Critical Vulnerabilities in Popular Children’s Device
A children’s tablet marketed as a safe digital playground has been found to contain serious security and privacy risks, according to a recent investigation by cybersecurity expert Alexis Hancock of the Electronic Frontier Foundation (EFF). The findings reveal how budget-friendly devices may compromise children’s sensitive information.
The Troubling Discovery
Hancock’s examination of the Dragon Touch KidzPad Y88X uncovered multiple concerning issues:
- Pre-installed malware traces (Corejava) previously identified in compromised Android TV boxes
- Outdated Android OS (5 years old) with known security vulnerabilities
- Adups software classified as malware due to its ability to download unauthorized applications
- Obsolete version of KIDOZ app store collecting extensive device and usage data
“Parents shouldn’t need technical expertise to protect their children’s privacy,” Hancock told TechCrunch. “These findings show how vulnerable devices can slip through quality control checks.”
How the Tablet Compromises Children’s Privacy
1. Embedded Malware Risks
The tablet contained traces of Corejava malware, which cybersecurity firm Malwarebytes previously identified as malicious. While currently inactive, the malware was programmed to communicate with dormant servers, creating potential future risks.
2. Questionable Pre-installed Software
The Adups firmware update tool, classified as a “potentially unwanted program,” could automatically download and install new malware without user consent.
3. Data Collection Practices
The outdated KIDOZ app store collected:
- Device specifications (model, brand, screen size)
- Location data (country, timezone)
- Usage patterns (click events, view events)
- Unique identifiers (KID ID)
KIDOZ maintains its compliance with COPPA (Children’s Online Privacy Protection Act) through PRIVO certification, but security experts question whether outdated versions maintain these protections.
Marketplace Response and Accountability
Both Amazon and Walmart removed the tablet from their platforms after being contacted by TechCrunch. Key responses:
- Amazon: “Looking into these claims and will take appropriate action”
- Walmart: Removed the item pending Trust and Safety review
- Google: Evaluating whether the device meets Play Protect certification standards
Dragon Touch, listed as an Android-certified partner, failed to respond to multiple contact attempts regarding these security concerns.
A History of Vulnerable Children’s Tech
This incident follows a pattern of security issues with children’s connected devices:
- 2015 VTech breach exposing data of 5 million parents and 200,000 children
- Recent findings of malware in budget Android TV boxes
Protecting Your Child’s Digital Safety
Hancock implemented several security measures for her daughter’s tablet:
- Installed a VPN with Pi-hole ad blocking
- Restricted app access
- Modified DNS settings
- Added Tor browser for anonymous browsing
However, she emphasizes: “Parents shouldn’t bear this responsibility alone. Manufacturers must prioritize security in children’s products from the design phase.”
The Bigger Picture
This case highlights critical questions about:
- Certification processes for “child-safe” devices
- Marketplace accountability for third-party sellers
- The need for stronger regulations around children’s digital products
As connected devices become ubiquitous in children’s lives, security researchers urge manufacturers and retailers to implement more rigorous safety standards.
For security researchers: TechCrunch welcomes tips about device vulnerabilities via Signal, Telegram, Keybase, Wire, or SecureDrop.
📚 Featured Products & Recommendations
Discover our carefully selected products that complement this article’s topics:
🛍️ Featured Product 1: Avid Matchmaker X Pair Black Stainless Black Bolt Pair
Image: Premium product showcase
Carefully crafted avid matchmaker x pair black stainless black bolt pair delivering superior performance and lasting value.
Key Features:
- Premium materials and construction
- User-friendly design and operation
- Reliable performance in various conditions
- Comprehensive quality assurance
🔗 View Product Details & Purchase
💡 Need Help Choosing? Contact our expert team for personalized product recommendations!