ZeroHour

CVE-2026-18058

mass

Missing authorization in Lenovo Smart Connect mobile dashboard enables UI spoofing

CVSS 4.0
7.3 high
EPSS
<1%p0
Published
()
Modified
AI analysis

Lenovo Smart Connect's mobile dashboard UI lacks proper authorization checks (CWE-862), allowing third-party apps installed on the same mobile device to manipulate what the dashboard displays. Exploitation requires a malicious or compromised app already on the device, user interaction, and is typically combined with a phishing attack, which is reflected in the CVSS 4.0 score of 7.3 (High) with local attack vector, high attack complexity, and user interaction required. An attacker who succeeds gains escalated privileges within the system, with the CVSS vector indicating potentially high impact on confidentiality, integrity, and availability. Users running the Smart Connect mobile app on their phones are affected; no specific affected version ranges are provided in the source data. There are no known public proof-of-concepts, no CISA KEV listing, and EPSS puts 30-day exploitation probability at just 0.1%, so exploitation is not currently observed.

What to do: Update the Smart Connect mobile app to the latest build available in Google Play/the App Store and check the Lenovo PSIRT advisory for the specific fixed versions. On devices where you use Smart Connect, audit installed third-party apps holding overlay ('display over other apps') or Accessibility permissions, since these are typical UI-manipulation vectors. Treat unexpected dashboard prompts for credentials or approvals as potentially spoofed, especially when they follow a phishing email or message.

Affected
Lenovo Smart Connect mobile app (dashboard UI)
Estimated exposure
mass≈1M+ mobile users (upper-bound estimate; app is a stock cross-device companion on Lenovo/Motorola devices with on the order of 1M+ Google Play installs) — Smart Connect is the default phone-to-PC companion app bundled with recent Motorola/Lenovo hardware and carries roughly 1M+ Google Play installs, though only a subset actively uses the mobile dashboard and exploitation additionally…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privileges of an attacker within the system.

Weakness
CWE-862
Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.