Linecorp / Line
75 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-3861 | LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level di… | HIGH | 7.1 | Apr 16, 2026 |
| CVE-2025-14023 | LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could… | MEDIUM | 4.3 | Dec 15, 2025 |
| CVE-2025-14022 | LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK inter… | HIGH | 7.7 | Dec 15, 2025 |
| CVE-2025-14021 | The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaS… | MEDIUM | 4.3 | Dec 15, 2025 |
| CVE-2025-14020 | LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is… | MEDIUM | 5.4 | Dec 15, 2025 |
| CVE-2025-14019 | LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen war… | MEDIUM | 4.7 | Dec 15, 2025 |
| CVE-2024-5739 | The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripti… | MEDIUM | 6.1 | Jun 12, 2024 |
| CVE-2023-48135 | An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 26, 2024 |
| CVE-2023-48133 | An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 26, 2024 |
| CVE-2023-48132 | An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the chann… | MEDIUM | 5.4 | Jan 26, 2024 |
| CVE-2023-48131 | An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 26, 2024 |
| CVE-2023-48130 | An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 26, 2024 |
| CVE-2023-48129 | An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 26, 2024 |
| CVE-2023-48128 | An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 26, 2024 |
| CVE-2023-48127 | An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 26, 2024 |
| CVE-2023-48126 | An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 26, 2024 |
| CVE-2023-44001 | An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 24, 2024 |
| CVE-2023-44000 | An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 24, 2024 |
| CVE-2023-43999 | An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 24, 2024 |
| CVE-2023-43998 | An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 24, 2024 |
| CVE-2023-43997 | An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 24, 2024 |
| CVE-2023-43996 | An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 24, 2024 |
| CVE-2023-43995 | An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 24, 2024 |
| CVE-2023-43994 | An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 24, 2024 |
| CVE-2023-43993 | An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | MEDIUM | 5.4 | Jan 24, 2024 |
Showing 1 to 25 of 75 CVEs