CVE-2025-14021

The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
References
Link Resource
https://hackerone.com/reports/2548498 Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:*

History

No history.

Information

Published : 2025-12-15 07:15

Updated : 2025-12-18 02:01


NVD link : CVE-2025-14021

Mitre link : CVE-2025-14021

CVE.ORG link : CVE-2025-14021


JSON object : View

Products Affected

linecorp

  • line
CWE
CWE-451

User Interface (UI) Misrepresentation of Critical Information