CVE-2025-14021

The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
References
Link Resource
https://hackerone.com/reports/2548498 Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:*

History

18 Dec 2025, 02:01

Type Values Removed Values Added
References () https://hackerone.com/reports/2548498 - () https://hackerone.com/reports/2548498 - Permissions Required, Third Party Advisory
CPE cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:*
First Time Linecorp
Linecorp line

15 Dec 2025, 16:15

Type Values Removed Values Added
CWE CWE-451

15 Dec 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-15 07:15

Updated : 2025-12-18 02:01


NVD link : CVE-2025-14021

Mitre link : CVE-2025-14021

CVE.ORG link : CVE-2025-14021


JSON object : View

Products Affected

linecorp

  • line
CWE
CWE-451

User Interface (UI) Misrepresentation of Critical Information