CVE-2025-14022
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a significant portion of network traffic, which could allow a network-adjacent attacker to intercept or modify encrypted communications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14022?
CVE-2025-14022 has a high severity rating due to the potential for man-in-the-middle attacks.
How do I fix CVE-2025-14022?
To fix CVE-2025-14022, update the LINE client for iOS to version 15.4 or later.
What type of vulnerabilities does CVE-2025-14022 present?
CVE-2025-14022 presents man-in-the-middle vulnerabilities due to improper SSL/TLS certificate validation.
Who is affected by CVE-2025-14022?
Users of the LINE client for iOS versions prior to 15.4 are affected by CVE-2025-14022.
What is the impact of CVE-2025-14022 on users?
The impact of CVE-2025-14022 includes potential interception of sensitive information due to disabled certificate verification.