Impact
A code injection flaw in the LINE Android application allows an attacker to embed malicious script into a user profile. When a victim views such a crafted profile, the embedded script executes with the application’s privileges, enabling arbitrary code execution on the device. The vulnerability stems from insufficient validation or sandboxing of external script content in the profile rendering component, thereby exposing the app to exploitation that could compromise confidentiality, integrity, or availability of user data.
Affected Systems
The LINE client for Android is affected. All installations of the app prior to version 26.7.2 are vulnerable. Users must assure that their app is upgraded to the latest release to avoid exposure.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector requires an attacker to place malicious content in a profile, which a victim later views. This suggests a social engineering or targeted profile-based threat model, where the victim must interact with a seemingly legitimate profile for exploitation to occur. The server‑side mitigation already in place provides a secondary defense for unpatched clients.
OpenCVE Enrichment