Loading HuntDB...

GHSA-g7x3-mc24-pxm6

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions.

Version 1.4.4 is vulnerable, vendor reverted vulnerable versions to older version: 1.3.6

Related CVEs

Key Information

GHSA ID
GHSA-g7x3-mc24-pxm6
Published
July 17, 2025 3:32 PM
Last Modified
July 17, 2025 3:32 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 26, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.