CVE-2026-18058
massMissing authorization in Lenovo Smart Connect mobile dashboard enables UI spoofing
Lenovo Smart Connect's mobile dashboard UI lacks proper authorization checks (CWE-862), allowing third-party apps installed on the same mobile device to manipulate what the dashboard displays. Exploitation requires a malicious or compromised app already on the device, user interaction, and is typically combined with a phishing attack, which is reflected in the CVSS 4.0 score of 7.3 (High) with local attack vector, high attack complexity, and user interaction required. An attacker who succeeds gains escalated privileges within the system, with the CVSS vector indicating potentially high impact on confidentiality, integrity, and availability. Users running the Smart Connect mobile app on their phones are affected; no specific affected version ranges are provided in the source data. There are no known public proof-of-concepts, no CISA KEV listing, and EPSS puts 30-day exploitation probability at just 0.1%, so exploitation is not currently observed.
What to do: Update the Smart Connect mobile app to the latest build available in Google Play/the App Store and check the Lenovo PSIRT advisory for the specific fixed versions. On devices where you use Smart Connect, audit installed third-party apps holding overlay ('display over other apps') or Accessibility permissions, since these are typical UI-manipulation vectors. Treat unexpected dashboard prompts for credentials or approvals as potentially spoofed, especially when they follow a phishing email or message.
| Lenovo Smart Connect mobile app (dashboard UI) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privileges of an attacker within the system.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.