VYPR
Medium severity5.4NVD Advisory· Published Dec 15, 2025· Updated Jun 17, 2026

CVE-2025-14020

CVE-2025-14020

Description

LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not properly re-displayed when users return from another application, potentially allowing attackers to conduct phishing attacks by impersonating legitimate interfaces.

Affected products

3
  • cpe:2.3:a:linecorp:line:*:*:*:*:*:android:*:*
    Range: <14.20.0
  • N-LINE/N-LINEllm-fuzzy
    Range: <14.20
  • LINE Corporation/LINE client for Androidv5
    Range: 10.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.