Bluebird File Manager Unsecured AIDL Service Vulnerability Allowing Arbitrary File Manipulation

Vulnerability

A vulnerability exists in the pre-loaded file manager application on Bluebird devices, specifically in version 1.4.4. The application exposes an unsecured AIDL-type service provider, 'com.bluebird.system.koreanpost.IsdcardRemoteService', which allows local attackers to bind to the service and gain system-level permissions to copy and delete arbitrary files from the device's storage.

Impact

Exploitation of this vulnerability allows for unauthorized copying and deletion of files on the device, with system-level permissions.

Remediation

Users can downgrade to version 1.3.6, which is not vulnerable, as the vendor has reverted vulnerable versions to this earlier release.

Added: Jul 17, 2025, 1:17 PM
Updated: Jul 17, 2025, 1:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.