Impact
The Lenovo File Manager Android Application contains an improper authorization flaw where a local authenticated user can read or modify protected files within the app. This grants an attacker unauthorized access, potentially exposing sensitive data or altering application behavior. The weakness corresponds to CWE‑926.
Affected Systems
The vulnerability affects the Lenovo File Manager Android Application sold in the Chinese market. All releases prior to version 9.8.1.77 are impacted. Updated releases starting with 9.8.1.77 contain the fix.
Risk and Exploitability
With a CVSS score of 8.4, the bug is high severity. The EPSS score is not provided and the issue is not listed in CISA KEV. Because the flaw arises from missing authorization checks (CWE‑926), it can be exploited by any local user who can launch the app; no remote exploitation is reported. An attacker controlling the device or with local privileges can perform read or modify operations on protected files without additional prerequisites.
OpenCVE Enrichment