The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/2548498 | Permissions Required Third Party Advisory |
Configurations
History
18 Dec 2025, 02:01
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://hackerone.com/reports/2548498 - Permissions Required, Third Party Advisory | |
| CPE | cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:* | |
| First Time |
Linecorp
Linecorp line |
15 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-451 |
15 Dec 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-15 07:15
Updated : 2025-12-18 02:01
NVD link : CVE-2025-14021
Mitre link : CVE-2025-14021
CVE.ORG link : CVE-2025-14021
JSON object : View
Products Affected
linecorp
- line
CWE
CWE-451
User Interface (UI) Misrepresentation of Critical Information
