Junglewise Threat Intelligence

CVE-2026-7516: Lenovo Android Application clipboard overwrite in built-in browser

CVE-2026-7516 · Severity: medium · CVSS 4.3 · Published 2026-06-10

Vendors: Lenovo.

Executive brief

A security vulnerability has been identified in a Lenovo application pre-installed on Android tablets sold in the Chinese market. This flaw allows malicious websites visited through the app's built-in browser to automatically change the contents of the device's system clipboard. This could lead to "clipboard hijacking," where a user might unknowingly paste malicious links or incorrect information into other applications.

Technical details

The Lenovo Android Application, specifically the version distributed on tablets in the Chinese market, contains a vulnerability classified as an 'Exposed Dangerous Method or Function' (CWE-749). The flaw exists within the application's built-in browser component, which fails to properly restrict clipboard access. A remote attacker can craft a malicious website that, when visited by a user, programmatically overwrites the system clipboard. This is achieved without requiring special privileges, though it does require the user to navigate to the attacker-controlled site. The primary impact is unauthorized modification of data (Integrity), which can be leveraged for phishing or redirecting user actions.

Affected products

  • Lenovo Lenovo Android Application (Tablet version) Chinese market specific models

Timeline

  • 2026-06-10: disclosed: Initial publication of the CVE record

References