CVE-2025-10495: Lenovo App Store
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code.
Affected products
- Lenovo App Store: before 9.0.2530.1027 (fixed in 9.0.2530.1027)
- Lenovo Browser: before 9.0.6.9111 (fixed in 9.0.6.9111)
- Lenovo Legion Zone: before 2.0.21 (fixed in 2.0.21)
- Lenovo Pc Manager: before 5.1.140.9262 (fixed in 5.1.140.9262)
Published 2025-11-12. Last modified 2026-06-17.