LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.

Project Subscriptions

Vendors Products
Line Corporation Subscribe
Line Client For Ios Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Thu, 30 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Title Repeated OS Dialog Trigger Causing Temporary iOS Device Inoperability via LINE In‑App Browser

Thu, 30 Apr 2026 11:15:00 +0000

Type Values Removed Values Added
Description LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs, potentially causing the iOS device to become temporarily inoperable. LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}


Fri, 17 Apr 2026 05:15:00 +0000

Type Values Removed Values Added
Title iOS Device Denial of Service via Repeated OS Dialogs in LINE In‑App Browser
Weaknesses CWE-835

Thu, 16 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Apr 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Line Corporation
Line Corporation line Client For Ios
Vendors & Products Line Corporation
Line Corporation line Client For Ios

Thu, 16 Apr 2026 09:15:00 +0000

Type Values Removed Values Added
Title iOS Device Denial of Service via Repeated OS Dialogs in LINE In‑App Browser
Weaknesses CWE-835

Thu, 16 Apr 2026 06:30:00 +0000

Type Values Removed Values Added
Description LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs, potentially causing the iOS device to become temporarily inoperable.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: LY-Corporation

Published:

Updated: 2026-05-12T00:54:07.069Z

Reserved: 2026-03-10T05:02:39.735Z

Link: CVE-2026-3861

cve-icon Vulnrichment

Updated: 2026-04-16T12:16:07.683Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-16T07:16:30.090

Modified: 2026-04-30T11:16:21.213

Link: CVE-2026-3861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T14:15:40Z

Weaknesses