A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content.
Fixes

Solution

The vulnerable Lenovo Browser component was updated automatically. No user action is required.


Workaround

No workaround given by the vendor.

References
History

Fri, 18 Jul 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Jul 2025 19:30:00 +0000

Type Values Removed Values Added
Description A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-07-17T20:08:01.388Z

Reserved: 2025-06-18T18:33:45.443Z

Link: CVE-2025-6248

cve-icon Vulnrichment

Updated: 2025-07-17T20:07:58.075Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-17T20:15:31.863

Modified: 2025-07-17T21:15:50.197

Link: CVE-2025-6248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.