
GLM-5.3 rooted a Fire tablet No zero-days needed, just a known CVE-2022-38181, fixed by Arm, cataloged by CISA in 2023, and patched by Amazon in 2024. The device itself wasn't not patched and after a hint about the CVE from Kimi K3, GLM finished the work. The story itself is just fun to read, link below. My thoughts: 1️⃣ The current gen of Kimi and GLM is already usable for finding and chaining vulnerabilities. My guess is that they're probably ~6m behind the closed frontier models and impose significantly less restrictions than them. 2️⃣ I wrote before, that I feel very uncomfortable when someone else decides what I can and can't do within legal boundaries. In this case, Claude and GPT refused to handle the actually legitimate request. The DMCA exemptions are valid through October 2027. The over firing Fable 5 and Opus 5 safeguards are making the models unusable. I'm not talking about any cyber activities, Claude refuses even to read papers about security. OpenAI verification that unlocks Daybreak Blue actually makes GPT-5.6-Sol more usable for my task! 3️⃣ I'm not sure if the open-weight models survive in mid-term. If the regulations start requiring all capable AI models to go through pre-launch testing and meet the same "centralized" safeguards that Dario is pushing for, there's just no space for the open-weight models at all. https://ericpardee.github.io/fire-hd-ownership/
Post summary
The post recounts a story where GLM‑5.3 successfully rooted an Amazon Fire tablet using the known CVE‑2022‑38181, noting that a patch existed but the device remained unpatched; no detailed exploit, PoC, or evidence of widespread active exploitation is provided.

