The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/2548498 | Permissions Required Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-12-15 07:15
Updated : 2025-12-18 02:01
NVD link : CVE-2025-14021
Mitre link : CVE-2025-14021
CVE.ORG link : CVE-2025-14021
JSON object : View
Products Affected
linecorp
- line
CWE
CWE-451
User Interface (UI) Misrepresentation of Critical Information
