SSL-busting code that threatened Lenovo users found in a dozen more apps
“What all these applications have in common is that they make people less secure.” — The list of software known to use the same HTTPS-breaking technology recently found preinstalled on Lenovo laptops has risen dramatically …
Context & Ripple Effects
Four days after researchers revealed that Superfish adware preinstalled on Lenovo notebooks was silently breaking HTTPS for Chrome and Internet Explorer users, the problem has grown from one vendor's bundle to a class of software: a dozen more applications ship the same certificate-injecting interception code.
The finding lands while Superfish is publicly insisting its HTTPS-busting adware poses no security risk, making this expansion of the affected-app list a direct rebuttal — and an early look at what would later become a broader audit of insecure preinstalled software across top PC vendors.
First-order effects
- Users of the newly identified dozen apps are exposed to man-in-the-middle attacks today, since the shared code lets any holder of its private key impersonate trusted HTTPS sites in their browsers.
- Superfish's no-risk position becomes untenable: the same interception technique is now documented outside its own product, reframing it from a single vendor's adware to reusable attack tooling.
Second-order effects
- Every major OEM that bundles third-party Windows software faces renewed scrutiny of its preload stack — scrutiny that later materialized when Duo Labs found known-insecure bloatware shipping on Lenovo, Acer, HP, Dell, and Asus machines, prompting Lenovo to tell users to uninstall its vulnerable Accelerator app.
- Security researchers shift attention from malware downloaded by users to software installed before first boot, turning OEM preload practices into a standing audit target rather than an occasional exposé.
Third-order effects
- If the pattern holds, 'value-added' preinstalled software becomes a priced-in liability for the PC industry: vendors absorb reputational and remediation costs for bundles they didn't write, pushing them toward cleaner images or contractual security vetting of partners.
- The episode foreshadows a durable category — dual-use interception code that is marketed as a feature but functions as attack infrastructure — which later resurfaces in the anti-theft rootkit Lenovo shipped that reinstalled unwanted software.
The trend: Preloaded PC software is shifting from a monetization afterthought to a systemic security liability, with researchers and vendors converging on preload audits as standard practice.