CVE-2026-3861Medium· 6.5▾ SunlitLINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, pote…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.
line < 26.3.0Upgrade past the affected range:
line 26.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-11748MediumCentral Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion
CVE-2026-11752MediumArmeria: External Control of File Name or Path in xDS SDS DataSource
CVE-2026-45650Medium· 4.3Microsoft Bing Search Spoofing Vulnerability
CVE-2026-94183High· 7.4Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background
CVE-2026-94181High· 7.4An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.
CVE-2024-52270High· 8.2PDF Document Spoofing in DropBox Sign(HelloSign)