CVE-2025-12046: Lenovo App Store

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions.

Affected products

  • Lenovo App Store: before 9.0.2530.1027 (fixed in 9.0.2530.1027)
  • Lenovo Browser: before 9.0.6.11071 (fixed in 9.0.6.11071)

Published 2025-12-10. Last modified 2026-09-25.