{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lenovo-health-android-application/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lenovo:health:*:*:*:*:*:android:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-75940"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Lenovo Health Android Application"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Lenovo"],"content_html":"\u003cp\u003eA critical security vulnerability has been identified in the Lenovo Health Android application, which is distributed exclusively within the Chinese market. This security flaw, tracked as CVE-2026-75940, carries a CVSS v3.1 base score of 9.1, indicating a severe risk to data confidentiality. The vulnerability allows an unauthorized actor to bypass existing security controls and access sensitive health-related information stored or processed by the application. Because the application is regional, its impact is limited to users within China who have installed the software. Defenders should note that while no specific exploitation chain was provided by the National Vulnerability Database (NVD), the high severity and potential for data exfiltration mandate prompt investigation for unauthorized data access attempts within environments where this application is in use.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe risk to the privacy of users of the Lenovo Health Android application. Successful exploitation could result in the unauthorized disclosure and exfiltration of sensitive health records, potentially impacting a large user base within the Chinese market.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize inventory management to identify all instances of the Lenovo Health Android application in mobile device management (MDM) solutions. Since the application is restricted to the Chinese market, verify if it is present on any corporate-managed mobile devices within your organization. If identified, restrict the application's network access or remove it until a patch is confirmed and applied. Monitor mobile device logs for any abnormal data access patterns or unauthorized requests originating from the Lenovo Health application package name.\u003c/p\u003e\n","date_modified":"2026-09-10T23:09:27Z","date_published":"2026-09-10T23:09:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lenovo-health-vuln/","summary":"A high-severity vulnerability in the Lenovo Health Android application, exclusively distributed in the Chinese market, allows unauthorized access to sensitive user health data.","title":"Critical Vulnerability in Lenovo Health Android Application","url":"https://feed.craftedsignal.io/briefs/2026-09-lenovo-health-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Lenovo Health Android Application","version":"https://jsonfeed.org/version/1.1"}