CVE-2025-14019
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-15

Last updated on: 2025-12-19

Assigner: LINE Corporation

Description
LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen warning prompt, potentially allowing attackers to conduct phishing attacks.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-15
Last Modified
2025-12-19
Generated
2026-05-07
AI Q&A
2025-12-15
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
linecorp line From 13.8.0 (inc) to 15.5.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-451 The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects the LINE client for Android versions 13.8 to 15.5. It is a UI spoofing issue in the in-app browser where a specific layout can hide the full-screen warning prompt. This could allow attackers to trick users by displaying fake content, potentially leading to phishing attacks.


How can this vulnerability impact me? :

The vulnerability can impact you by enabling attackers to perform phishing attacks through the in-app browser. Since the full-screen warning prompt can be obscured, users might be misled into trusting malicious content, which could lead to information theft or other security risks.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, update the LINE client for Android to a version later than 15.5 where the UI spoofing issue in the in-app browser is fixed. Avoid using the affected versions (13.8 to 15.5) until an update is applied. Additionally, educate users to be cautious of unexpected full-screen prompts within the app that could be phishing attempts.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart