We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions. Version 1.4.4 is vulnerable, vendor reverted vulnerable versions to older version: 1.3.6
Reserved 2025-05-30 | Published 2025-07-17 | Updated 2025-07-17 | Assigner CERT-PLCWE-926 Improper Export of Android Application Components
Szymon Chadam
cert.pl/en/posts/2025/07/CVE-2025-5344
Support options