Lenovo PC Manager, Browser, and App Store Potential TOCTOU Vulnerability Leading to System Crash

Vulnerability

A potential time-of-check to time-of-use (TOCTOU) vulnerability has been identified in Lenovo PC Manager, Lenovo Browser, and the Lenovo App Store. This vulnerability could allow a local attacker to cause a system crash.

Impact

Exploitation of this vulnerability can lead to a system crash, causing a denial-of-service condition.

Remediation

Users are advised to update Lenovo PC Manager to version 5.1.90.12092 or later, Lenovo Browser to version 9.0.5.12181 or later, and the Lenovo App Store to version 9.0.20 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
2.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.