CVE-2025-5344: Bluebird Com.bluebird.kiosk.launcher

High severity, CVSS 8.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image. This issue affects all versions before 1.1.2.

Affected products

  • Bluebird Com.bluebird.kiosk.launcher: before 1.1.2 (fixed in 1.1.2)

Published 2025-07-17. Last modified 2026-06-17.