Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://hackerone.com/reports/2853445 |
|
Thu, 18 Dec 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:* |
Mon, 15 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios Linecorp Linecorp line |
|
| Vendors & Products |
Apple
Apple ios Linecorp Linecorp line |
Mon, 15 Dec 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a significant portion of network traffic, which could allow a network-adjacent attacker to intercept or modify encrypted communications. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: LY-Corporation
Published:
Updated: 2026-01-07T15:07:56.850Z
Reserved: 2025-12-04T11:45:01.936Z
Link: CVE-2025-14022
Updated: 2025-12-15T18:45:32.295Z
Status : Modified
Published: 2025-12-15T07:15:50.980
Modified: 2026-01-07T16:15:49.130
Link: CVE-2025-14022
No data.
OpenCVE Enrichment
Updated: 2025-12-15T14:05:27Z