Executive brief
A security vulnerability has been identified in a Lenovo application pre-installed on Android tablets sold in the Chinese market. This flaw allows malicious websites visited through the app's built-in browser to automatically change the contents of the device's system clipboard. This could lead to "clipboard hijacking," where a user might unknowingly paste malicious links or incorrect information into other applications.
Technical details
The Lenovo Android Application, specifically the version distributed on tablets in the Chinese market, contains a vulnerability classified as an 'Exposed Dangerous Method or Function' (CWE-749). The flaw exists within the application's built-in browser component, which fails to properly restrict clipboard access. A remote attacker can craft a malicious website that, when visited by a user, programmatically overwrites the system clipboard. This is achieved without requiring special privileges, though it does require the user to navigate to the attacker-controlled site. The primary impact is unauthorized modification of data (Integrity), which can be leveraged for phishing or redirecting user actions.
Affected products
- Lenovo Lenovo Android Application (Tablet version) Chinese market specific models
Timeline
- 2026-06-10: disclosed: Initial publication of the CVE record