Unauthenticated attackers can repurpose old Android devices (e.g., drawer phones) as malicious surveillance tools by exploiting default or weak configurations in outdated firmware. This allows unauthorized access to camera feeds, microphone recordings, and stored data, impacting any user who reuses or resells an unsecured Android device without factory reset or firmware updates.