CVE-2025-8485: Lenovo App Store

High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.

An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application.

Affected products

  • Lenovo App Store: before 9.0.2530.1027 (fixed in 9.0.2530.1027)

Published 2025-11-12. Last modified 2026-06-17.