CVE-2026-3861

LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.
References
Link Resource
https://hackerone.com/reports/3422905 Permissions Required
Configurations

Configuration 1 (hide)

cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:*

History

No history.

Information

Published : 2026-04-16 07:16

Updated : 2026-07-08 03:29


NVD link : CVE-2026-3861

Mitre link : CVE-2026-3861

CVE.ORG link : CVE-2026-3861


JSON object : View

Products Affected

linecorp

  • line
CWE
CWE-451

User Interface (UI) Misrepresentation of Critical Information