Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerable Lenovo Browser component was updated automatically. No user action is required.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21800 | A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content. |
| Link | Providers |
|---|---|
| https://iknow.lenovo.com.cn/detail/430154 |
|
Fri, 18 Jul 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Jul 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2025-07-17T20:08:01.388Z
Reserved: 2025-06-18T18:33:45.443Z
Link: CVE-2025-6248
Updated: 2025-07-17T20:07:58.075Z
Status : Deferred
Published: 2025-07-17T20:15:31.863
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-6248
No data.
OpenCVE Enrichment
No data.
EUVD