{"id":"CVE-2025-14022","title":"LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK","summary":"LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate ve…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","cwe":["CWE-295","CWE-295"],"vendor":"linecorp","product":"line","affected":["line < 15.4.0"],"patched":["line 15.4.0"],"published":"2025-12-15","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:10:00.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14022","references":[{"url":"https://hackerone.com/reports/2853445","label":"dl_cve@linecorp.com"}],"tags":["nvd"],"epss":0.00162,"epssPercentile":0.04836,"ingestedAt":"2026-10-07T19:44:15.682Z","slug":"CVE-2025-14022","body":"## Overview\n\nLINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a significant portion of network traffic, which could allow a network-adjacent attacker to intercept or modify encrypted communications.\n\n## Affected\n\n- `line < 15.4.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `line 15.4.0`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}