---
id: CVE-2025-14021
title: >-
  The in-app browser in LINE client for iOS versions prior to 14.14 is
  vulnerable to address bar spoofing, which could allow attackers to execute
  malicious JavaScript within iframes while displaying trusted URLs, enabling
  phishing attacks …
summary: >-
  The in-app browser in LINE client for iOS versions prior to 14.14 is
  vulnerable to address bar spoofing, which could allow attackers to execute
  malicious JavaScript within iframes while displaying trusted URLs, enabling
  phishing attacks …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-451
vendor: linecorp
product: line
affected:
  - line < 14.14.0
patched:
  - line 14.14.0
published: '2025-12-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14021'
references:
  - url: 'https://hackerone.com/reports/2548498'
    label: dl_cve@linecorp.com
tags:
  - nvd
epss: 0.00212
epssPercentile: 0.10468
ingestedAt: '2026-10-07T19:44:15.681Z'
---

## Overview

The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.

## Affected

- `line < 14.14.0`

## Remediation

Upgrade past the affected range:

- `line 14.14.0`
