<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>File Manager (Chinese Market Distribution) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/file-manager-chinese-market-distribution/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 23:10:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/file-manager-chinese-market-distribution/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Authorization Vulnerability in Lenovo File Manager Android App</title><link>https://feed.craftedsignal.io/briefs/2026-09-lenovo-file-manager-vuln/</link><pubDate>Thu, 10 Sep 2026 23:10:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-lenovo-file-manager-vuln/</guid><description>A local improper authorization vulnerability in the Lenovo File Manager Android app allows authenticated local users to read or modify protected application files.</description><content:encoded><![CDATA[<p>An improper authorization vulnerability (CVE-2026-18994) has been identified in the Lenovo File Manager Android application. This vulnerability is specific to the version of the application distributed within the Chinese market. It allows a local, authenticated user to bypass existing authorization controls, granting them the ability to read or modify protected files maintained by the application. This could lead to unauthorized data exposure or manipulation of sensitive user data stored within the app's directory. Defenders should note that this is a local attack vector requiring the adversary to have already gained access to the mobile device or have an application running with sufficient permissions to interface with the Lenovo File Manager.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects the Lenovo File Manager application distributed in the Chinese market. Successful exploitation allows a local user to gain unauthorized access to protected file resources, potentially resulting in data exfiltration or corruption. The CVSS base score for this vulnerability is 7.1.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of Lenovo File Manager installations on mobile devices managed within the organization. Check for updates provided via the official vendor channels for the Chinese market and apply patches immediately. As this is a local privilege escalation vector, audit Android permissions and ensure that only trusted applications are installed on devices that have access to corporate data.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>android</category><category>privilege-escalation</category></item></channel></rss>