The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/2548498 |
|
History
Mon, 15 Dec 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: LY-Corporation
Published:
Updated: 2025-12-15T06:45:46.378Z
Reserved: 2025-12-04T11:44:56.068Z
Link: CVE-2025-14021
No data.
Status : Received
Published: 2025-12-15T07:15:50.850
Modified: 2025-12-15T07:15:50.850
Link: CVE-2025-14021
No data.
OpenCVE Enrichment
No data.