CVE-2026-3861

MEDIUM

LINE client for iOS < 26.3.0 - Denial of Service via In-App Browser URL Scheme Handling

Title source: llm
STIX 2.1

Description

LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0031
EPSS Percentile 21.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-451
Status published
Products (2)
LINE Corporation/LINE client for iOS - - 26.3.0
LY Corporation/LINE client for iOS 26.3.0
Published Apr 16, 2026
Tracked Since Apr 16, 2026