The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/2548498 |
|
History
Mon, 15 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-451 | |
| Metrics |
ssvc
|
Mon, 15 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios Linecorp Linecorp line |
|
| Vendors & Products |
Apple
Apple ios Linecorp Linecorp line |
Mon, 15 Dec 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: LY-Corporation
Published: 2025-12-15T06:41:37.992Z
Updated: 2025-12-15T15:49:07.716Z
Reserved: 2025-12-04T11:44:56.068Z
Link: CVE-2025-14021
Updated: 2025-12-15T15:49:00.538Z
Status : Awaiting Analysis
Published: 2025-12-15T07:15:50.850
Modified: 2025-12-15T18:22:13.783
Link: CVE-2025-14021
No data.