Archetyp Links

Dark Mode

Article Details

Serious weak point: This AI grants hackers access to your Windows PC

Published on August 19, 2025

Lenovo devices are currently the goal of hackers.(Source: Credit: Samsung; Montage: Netzwelt) A critical vulnerability was discovered at Lenovo's Ki-Chatbot "Lena". Hackers can insert harmful code via manipulated inputs. Lenovo has now closed the gap, but the case shows how susceptible AI can be. With "Lena" Lenovo has introduced its own AI chat bot to answer customer questions automatically and help with support inquiries.However, as it shows, artificial intelligence (AI) is a bit too helpful and gives a sensitive information that can be misused for the takeover of Windows laptops. Microsoft warns around 700 million Windows users: Less than 60 days Last call to the Windows 11-update Microsoft turns to around 700 million Windows users with an important announcement.If you are affected, you will only have less than 60 days to act. However, the reason for this is not an error in the AI itself, but a security gap.This enables the inlet of Schadcodes and Hacker to use the way generated content generated by the chatbot is used for their purposes. Hacker attack through special questions According to the Cybernews security experts, the weak point enables the execution of so-called XSS attacks (cross-site scripting).Certain entries ensure that the chat bot generates unsafe HTML code. Virus protection 2025 in the hardship test: Who is really tight?The best antivirens suites 2025 6 providers, tens of promise: We have examined the current security suites and VPN extensions.Where you get real all -round protection - and who only attracts with cheap prices for the first year. In the worst case, access to the Lenovo customer support platform is opened.In addition, the takeover of active support agent sessions and the tapping of session cookies is permitted.Such cookies serve as login tokens to recognize users or support agents. If these tokens are stolen and abused, attackers can log in directly into support accounts, view messages, read data or even change the functions in the system - without users notice it at all.Ultimately, your Lenovo device will be an open book for the hackers. Lenovo reacts Lenovo was informed about the gap by the security experts and said he had reacted within a week.The affected systems have been updated, the parsing of chat answers was adapted and additional exams for incoming user inputs installed. Lenovo emphasized that there is no evidence that the weak point was actively exploited.Nevertheless, the incident is a serious example of how important security tests related to AI assistants are - especially for global brands with millions of users.