Unsecured Service Provider in Bluebird Devices Kiosk Application
CVE-2025-5344
8.5HIGH
What is CVE-2025-5344?
The Bluebird devices feature a kiosk application that includes an unsecured service provider identified as 'com.bluebird.kiosk.launcher.IpartnerKioskRemoteService.' This vulnerability allows local attackers to bind to the AIDL-type service, potentially enabling them to alter the device's global settings, including wallpaper images. All versions prior to 1.1.2 are subject to this risk.
Affected Version(s)
com.bluebird.kiosk.launcher Android 0 < 1.1.2