CVE-2025-14020
MEDIUMLINE client for Android <14.20 - CSRF
Title source: llmDescription
LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not properly re-displayed when users return from another application, potentially allowing attackers to conduct phishing attacks by impersonating legitimate interfaces.
Scores
CVSS v3
5.4
EPSS
0.0003
EPSS Percentile
8.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Classification
CWE
CWE-451
Status
published
Affected Products (1)
linecorp/line
< 14.20.0
Timeline
Published
Dec 15, 2025
Tracked Since
Feb 18, 2026