CVE-2025-14021
The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14021?
CVE-2025-14021 has been classified as a medium severity vulnerability due to its potential for enabling phishing attacks.
How do I fix CVE-2025-14021?
To fix CVE-2025-14021, upgrade the LINE client for iOS to version 14.14 or later.
What type of attack can be executed through CVE-2025-14021?
CVE-2025-14021 can be exploited to carry out address bar spoofing and phishing attacks using malicious JavaScript.
Which versions of LINE are affected by CVE-2025-14021?
CVE-2025-14021 affects LINE client for iOS versions prior to 14.14.
What is address bar spoofing in the context of CVE-2025-14021?
Address bar spoofing in CVE-2025-14021 refers to displaying trusted URLs while allowing malicious content to overlay the genuine content.