CVE-2026-75940
A critical flaw in the Lenovo Health Android app, sold only in China, lets attackers read private health data. The weakness is in how the app handles authentication, allowing unauthorized access. Users should be aware that their personal health information could be exposed.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Lenovo Health Android Application sold in the Chinese market.
Real-world impact
An attacker could read or steal users’ private health records, potentially revealing sensitive medical conditions or personal data.
Why this severity
The CVSS score of 9.3 reflects a high confidentiality impact with no authentication or user interaction required. Because the flaw lets anyone on the network read private data, it is considered critical.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources