Medium severity4.3NVD Advisory· Published Dec 15, 2025· Updated Jun 17, 2026
CVE-2025-14021
CVE-2025-14021
Description
The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
Affected products
3- LINE Corporation/LINE client for iOSv5Range: 14.13
- Range: <14.14
Patches
Vulnerability mechanics
References
1- hackerone.com/reports/2548498nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.