CVE-2024-10253: Lenovo App Store

Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.

A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.

Affected products

  • Lenovo App Store: before 9.0.20 (fixed in 9.0.20)
  • Lenovo Browser: before 9.0.5.12181 (fixed in 9.0.5.12181)
  • Lenovo Pc Manager: before 5.1.90.12092 (fixed in 5.1.90.12092)

Published 2025-01-14. Last modified 2026-06-17.