Description
Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image.
This issue affects all versions before 1.1.2.
This issue affects all versions before 1.1.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21763 | Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image. This issue affects all versions before 1.1.2. |
References
| Link | Providers |
|---|---|
| https://cert.pl/en/posts/2025/07/CVE-2025-5344 |
|
History
Thu, 17 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image. This issue affects all versions before 1.1.2. | |
| Title | Exposed AIDL service allowing for tampering of system secure settings in Bluebird kiosk application | |
| Weaknesses | CWE-926 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-07-17T13:48:07.955Z
Reserved: 2025-05-30T06:40:12.828Z
Link: CVE-2025-5344
Updated: 2025-07-17T13:47:08.172Z
Status : Deferred
Published: 2025-07-17T13:15:23.037
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-5344
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD