LINE client for iOS prior to 15.4 allows man-in-the...
High severity
Unreviewed
Published
Dec 15, 2025
to the GitHub Advisory Database
•
Updated Dec 15, 2025
Description
Published by the National Vulnerability Database
Dec 15, 2025
Published to the GitHub Advisory Database
Dec 15, 2025
Last updated
Dec 15, 2025
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a significant portion of network traffic, which could allow a network-adjacent attacker to intercept or modify encrypted communications.
References