Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pxq2-rvhg-7cp9

Опубликовано: 17 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image.

This issue affects all versions before 1.1.2.

Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image.

This issue affects all versions before 1.1.2.

EPSS

Процентиль: 4%
0.00018
Низкий

8.5 High

CVSS4

Дефекты

CWE-926

Связанные уязвимости

nvd
7 месяцев назад

Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image. This issue affects all versions before 1.1.2.

EPSS

Процентиль: 4%
0.00018
Низкий

8.5 High

CVSS4

Дефекты

CWE-926