PT-2026-67640 · Line · Line
CVE-2026-16881
·
Published
2026-08-04
·
Updated
2026-08-04
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LINE Android app versions prior to 26.7.2
Description
A code injection issue exists in the profile rendering component, which fails to properly validate or sandbox script content provided externally within profile templates. This allows an attacker to embed crafted content in a profile, leading to the execution of unintended code with the application's privileges when a victim views the profile.
Recommendations
Update to version 26.7.2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Line