Linecorp
Linecorp Line: vulnerabilidades y CVE
Linecorp Line tiene 75 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE75
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-3861 | Alta (7.1) | 0.34% | — | 16 abr 2026 | LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary… |
| CVE-2025-14023 | Media (4.3) | 0.18% | — | 15 dic 2025 | LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could create confusion about the trust context of displayed pages… |
| CVE-2025-14022 | Media (6.8) | 0.16% | — | 15 dic 2025 | LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing… |
| CVE-2025-14021 | Media (4.3) | 0.21% | — | 15 dic 2025 | The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling… |
| CVE-2025-14020 | Media (4.3) | 0.18% | — | 15 dic 2025 | LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not properly re-displayed when users return from another… |
| CVE-2025-14019 | Media (4.7) | 0.18% | — | 15 dic 2025 | LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen warning prompt, potentially allowing attackers to conduct… |
| CVE-2024-5739 | Media (6.1) | 0.27% | — | 12 jun 2024 | The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where arbitrary JavaScript can be executed in the… |
| CVE-2023-48129 | Media (5.4) | 0.36% | — | 26 ene 2024 | An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-48135 | Media (5.4) | 0.36% | — | 26 ene 2024 | An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-48133 | Media (5.4) | 0.36% | — | 26 ene 2024 | An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-48132 | Media (5.4) | 0.36% | — | 26 ene 2024 | An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-48131 | Media (5.4) | 0.36% | — | 26 ene 2024 | An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-48130 | Media (5.4) | 0.36% | — | 26 ene 2024 | An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-48128 | Media (5.4) | 0.36% | — | 26 ene 2024 | An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-48127 | Media (5.4) | 0.36% | — | 26 ene 2024 | An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-48126 | Media (5.4) | 0.36% | — | 26 ene 2024 | An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-44001 | Media (5.4) | 0.39% | — | 24 ene 2024 | An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-44000 | Media (5.4) | 0.36% | — | 24 ene 2024 | An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43999 | Media (5.4) | 0.39% | — | 24 ene 2024 | An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43998 | Media (5.4) | 0.40% | — | 24 ene 2024 | An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43997 | Media (5.4) | 0.36% | — | 24 ene 2024 | An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43996 | Media (5.4) | 0.39% | — | 24 ene 2024 | An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43995 | Media (5.4) | 0.36% | — | 24 ene 2024 | An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43994 | Media (5.4) | 0.36% | — | 24 ene 2024 | An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43993 | Media (5.4) | 0.39% | — | 24 ene 2024 | An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43992 | Media (5.4) | 0.36% | — | 24 ene 2024 | An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43991 | Media (5.4) | 0.39% | — | 24 ene 2024 | An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43990 | Media (5.4) | 0.39% | — | 24 ene 2024 | An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43989 | Media (5.4) | 0.36% | — | 24 ene 2024 | An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |
| CVE-2023-43988 | Media (5.4) | 0.38% | — | 24 ene 2024 | An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. |