> if your attack vector is just the software already on the device and java programs downloaded onto the device?
Any complex software has bugs. I would not be surprised if it would be easier to subvert a browser or JVM to execute arbitrary code than to get a root access from that code.