PT-2025-51206 · Line · Line Client For Ios

CVE-2025-14022

·

Published

2025-12-15

·

Updated

2025-12-15

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions LINE client for iOS versions prior to 15.4
Description The application experiences man-in-the-middle attacks because of flawed SSL/TLS certificate validation within an integrated financial SDK. The SDK disrupts the application’s network handling, disabling server certificate verification for a substantial amount of network traffic. This allows a network-based attacker to intercept or alter encrypted communications.
Recommendations Update the LINE client for iOS to version 15.4 or later.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14022

Affected Products

Line Client For Ios