Junglewise Threat Intelligence

CVE-2026-10588: Lenovo BIOS information disclosure in System Management Mode memory

CVE-2026-10588 · Severity: medium · CVSS 4.4 · Published 2026-07-16

Technologies: Lenovo Legion Pro 7 16AFR10H BIOS, Lenovo Legion Pro 5 16ADR10 BIOS, Lenovo LOQ 15ARP10E BIOS, Lenovo Yoga Book 9 14IAH10 BIOS, Lenovo Legion Pro 5 16AFR10 BIOS, Lenovo IdeaPad Pro 5 16IPH11 BIOS, Lenovo V15 G6 ARP BIOS, Lenovo Legion Pro 7 16ADR10H BIOS, Lenovo Legion 7 16AGP11 BIOS, Lenovo IdeaPad Pro 5 16AGP11 BIOS, Lenovo Yoga Pro 7 15IPH11 BIOS. Vendors: Lenovo.

Executive brief

A vulnerability in the BIOS firmware of various Lenovo laptops could allow an attacker with high-level administrative privileges to identify the location of highly protected system memory. This memory, known as System Management Mode (SMM), is typically isolated from the operating system to handle critical hardware functions. While this flaw does not allow direct modification of data, it provides information that could be used to bypass security protections and launch more sophisticated attacks against the device's core firmware.

Technical details

An information disclosure vulnerability exists in the BIOS firmware of multiple Lenovo laptop models. The flaw allows a local attacker with high privileges (e.g., administrative or root access) to determine the base address of System Management Mode (SMM) memory. SMM is a highly privileged execution environment intended to be transparent to the operating system. By disclosing these memory addresses, an attacker can bypass Address Space Layout Randomization (ASLR) or similar protections within the firmware, potentially facilitating subsequent exploitation of SMM vulnerabilities. Lenovo has released BIOS updates for affected models to mitigate this issue.

Affected products

  • Lenovo Yoga Pro 7 15IPH11 BIOS before TNCN37WW
  • Lenovo IdeaPad Pro 5 16IPH11 BIOS before S4CN62WW
  • Lenovo Legion 7 16AGP11 BIOS up to and including TPCN27WW
  • Lenovo IdeaPad Pro 5 16AGP11 BIOS up to and including T8CN19WW
  • Lenovo Legion Pro 5 16ADR10 BIOS up to and including U5CN07WW
  • Lenovo Lenovo V15 G6 ARP BIOS up to and including TYCN15WW
  • Lenovo LOQ 15ARP10E BIOS before SUCN18WW
  • Lenovo Yoga Book 9 14IAH10 BIOS up to and including QEME23WW
  • Lenovo Legion Pro 7 16AFR10H BIOS before SMCN20WW
  • Lenovo Legion Pro 5 16AFR10 BIOS up to and including RECN14WW
  • Lenovo Legion Pro 7 16ADR10H BIOS before SJCN17WW

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats