Executive brief
The LINE messaging app for iOS contains a flaw in its built-in web browser. If a user visits a malicious website through the app, the site can force the phone to display a continuous loop of system alerts. This can effectively freeze the device and make it unusable until the app is closed or the phone is restarted.
Technical details
A vulnerability exists in the in-app browser of the LINE iOS application due to insufficient safeguards when handling arbitrary URL schemes. By enticing a user to visit a specially crafted webpage, a remote attacker can trigger a loop of OS-level dialogs (CWE-451). This results in a denial-of-service condition where the device becomes temporarily inoperable due to the persistent UI interference. The issue is resolved in version 26.3.0.
Affected products
- LY Corporation LINE client for iOS versions prior to 26.3.0
Timeline
- 2026-04-16: disclosed
- 2026-04-16: advisory