
The play
Ten popular connected toys, from a kids' tablet to a Bluetooth-enabled puzzle cube to a story-playing audio box, were the subject of a security audit the Mozilla Foundation published on 19 December 2025 as part of its Nothing Personal series. Mozilla commissioned the cybersecurity firm 7ASecurity to test the Amazon Fire Kids Tablet, Emo Robot, GoCube Edge, Huawei Watch Kids 4, Miko Mini, PlayShifu Plugo Count, Powerup 4.0 Airplane, Sphero Mini Activity Kit, TickTalk 5, and Toniebox 1, chosen, the report says, for popularity and for being representative of features found across the wider connected-toy market.
What the evidence says
7ASecurity's audit found that some tested toys with voice features had vulnerabilities that could let an attacker intercept and alter the spoken responses sent back to a child, an issue the report names specifically in the Emo Robot. The report is explicit about the limits of this finding: it states that the audit did not find evidence the voice-injection attacks discovered among the ten toys could be carried out completely remotely, and that exploiting the flaw would require a position on the same Wi-Fi network, within Bluetooth range, or at a hostile internet provider, not an attack launched from anywhere online. Separately, the audit reported that four out of ten toys exposed sensitive data through insecure physical storage, pointing to manufacturers not using the most secure storage options for saved media or not encrypting files kept on internal or external storage. Mozilla's companion setup guide, published the same day, turns those findings into steps: changing default passwords, keeping a toy offline when it can work offline, disabling cameras, microphones, and location sharing when not in use, and checking how long a manufacturer commits to providing security updates. These are findings about the ten specific products tested; the report does not claim the same vulnerabilities exist in other connected toys it did not examine.
Age fit and safety
The report does not assign or revise an age range for any tested toy; several, including a kids' tablet and a story-playing box, are already marketed toward preschool and early-elementary ages by their manufacturers. The safety signal here is about network and storage security, not developmental fit, and the report frames the voice-hijacking risk as most relevant on insecure or shared public Wi-Fi rather than a typical home network using modern encryption.
What to look for
This is a summary of one audit's findings and its own companion guidance, not a verdict on any brand as a whole.
- Is the specific model under consideration one of the ten Mozilla and 7ASecurity actually tested, or a different model from the same maker?
- Does the home network use current Wi-Fi security, since several of the reported risks depend on network access?
- Does the manufacturer state how long it will keep providing security updates for the device?
A single independent audit of ten named products is stronger evidence than a marketing claim, but it still describes those ten products at the time they were tested, not the category of connected toys as a whole.
Sources & reading trail
States the ten named toys tested, the testing partner 7ASecurity, and the voice-injection and insecure-storage findings.
Source published: 19 December 2025 · Retrieved: 16 September 2026
Mozilla's own companion guidance translating the audit's findings into setup and privacy-policy checks for caregivers.
Source published: 19 December 2025 · Retrieved: 16 September 2026
Standards, recall notices, studies and records establish the entry; the what-to-look-for reading is Toy Almanac editorial analysis. This retrospective draft does not imply the site published on the event date.