Executive brief
The LINE Android messaging app contains a vulnerability in how it displays user profiles. An attacker can inject malicious code into a profile that executes when victims view it, potentially stealing personal data or performing actions on their behalf. LINE has deployed a server-side fix to protect users even if they haven't updated the app.
Technical details
The vulnerability is a code injection flaw in the profile rendering component of the LINE Android app (versions prior to 26.7.2). The component fails to adequately validate or sandbox externally supplied script content embedded in profile templates. An attacker with the ability to inject crafted content into a profile can cause arbitrary code to execute with the application's privileges when a victim views that profile. The attack requires network reachability and user interaction (viewing a malicious profile) but no authentication. A server-side mitigation has been deployed that protects unpatched clients.
Affected products
- LINE LINE before 26.7.2
Timeline
- 2026-08-04: disclosed