← Lenovo Group

2014–2015 Lenovo — Superfish VisualDiscovery adware; universal TLS MITM root on consumer PCs

2015 Unknown records affected Share on X

Data compromised

Risk to all TLS-protected sessions on affected machines (banking, webmail, corporate VPN web portals)—not a single centralized database exfiltration

Technical writeup

Security researchers showed that Lenovo had pre-installed Superfish VisualDiscovery (also branded WindowShopper) on large volumes of consumer laptops from September 2014 onward. The stack installed a non-unique trusted root CA and proxied HTTPS through Komodia-based decryption, creating a machine-wide man-in-the-middle surface: anyone who recovered the widely discussed private key material could mint browser-trusted certificates for arbitrary sites. US-CERT/CISA issued a public alert, and Lenovo later settled FTC and state AG claims plus a major consumer class action over the same behavior.

Root cause

Preinstalled ad-injection software that broke TLS trust by distributing shared private key material on endpoints

References