LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/3422905 |
Configurations
No configuration.
History
30 Apr 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable. |
16 Apr 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-451 |
16 Apr 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-16 07:16
Updated : 2026-04-30 11:16
NVD link : CVE-2026-3861
Mitre link : CVE-2026-3861
CVE.ORG link : CVE-2026-3861
JSON object : View
Products Affected
No product.
CWE
CWE-451
User Interface (UI) Misrepresentation of Critical Information
