LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Sep 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-449 | |
Metrics |
cvssV3_1
|
Wed, 03 Sep 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-03T20:16:03.564Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56139

No data.

Status : Received
Published: 2025-09-03T20:15:34.680
Modified: 2025-09-03T21:15:32.640
Link: CVE-2025-56139

No data.

No data.