Lenovo stops shipping Superfish adware with consumer devices

Superfish adware had potential to make browser data available to hackers

Lenovo has confirmed it has stopped shipping adware with its consumer laptops, which could have led to encrypted user data being compromised by hackers.

Known as Superfish', the program injected visual search results into the browser without user permission, according to forums unearthed by The Next Web.

While OEMs routinely install bloatware on Windows machines, the Superfish adware appeared to be dangerous, not just inconvenient. This is because it used a self-signed certificate, which if compromised, could have provided hackers with access to all browser data - regardless of whether it had been encrypted. 

Lenovo's official statement

"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns," the firm said in a statement.

"But we know that users reacted to this issue with concern, and so we have taken direct action to stop shipping any products with this software.

"We will continue to review what we do and how we do it in order to ensure we put our user needs, experience and priorities first."

Advertisement - Article continues below
Advertisement - Article continues below

A Lenovo forum administrator tried to allay fears by stating Superfish did not "profile nor monitor user behavior" or "record user information". The firm has now confirmed it has stopped shipping devices with the software.

Many Lenovo users have expressed their dismay at the inclusion of the software.

"I have been working in tech software and systems engineering since mice were not even available for personal computers. I have never seen a brand, of any sort, come OTB with malware," noted a perplexed Lenovo customer.

"This is just unreal...and altogether unacceptable. Lenovo is a brand I always have associated with top quality, best practices trustworthy security. The brand has been rock solid, but sliding for years, and lately I have been having some concerns about its Chinese home...increasingly concerning to me in light of technology security and attacks originating from China."

Below is a tutorial showing users how to uninstall the adware. Those affected are also encouraged to install a fresh copy of Windows to make sure the rogue security certificate is completely removed from their system.

The article was originally published on 19/2/15 and has been updated to reflect with the latest statements from Lenovo.

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now



The IT Pro Products of the Year 2019: All the year’s best hardware

24 Dec 2019
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019

Lenovo ThinkVision M14 review: The leanest screen

25 Nov 2019

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

mergers and acquisitions

Xerox to nominate directors to HP's board – reports

22 Jan 2020
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
public sector

UK gov launches £300,000 SEN EdTech initiative

22 Jan 2020
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020