CVE 4.3 MEDIUM

CVE-2025-14021_CVE-2025-14021

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.

Basic Information

ID CVE-2025-14021
Source LY-Corporation
Published Dec 15, 2025 at 06:41
Modified Dec 15, 2025 at 06:45

Affected Product

Vendor LINE Corporation
Product LINE client for iOS
Version 14.13
Affected Versions LINE Corporation LINE client for iOS 14.13

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.