Junglewise Threat Intelligence

CVE-2026-3861: LINE client for iOS denial of service in in-app browser

CVE-2026-3861 · Severity: medium · CVSS 6.5 · Published 2026-04-16

Vendors: LY Corporation.

Executive brief

The LINE messaging app for iOS contains a flaw in its built-in web browser. If a user visits a malicious website through the app, the site can force the phone to display a continuous loop of system alerts. This can effectively freeze the device and make it unusable until the app is closed or the phone is restarted.

Technical details

A vulnerability exists in the in-app browser of the LINE iOS application due to insufficient safeguards when handling arbitrary URL schemes. By enticing a user to visit a specially crafted webpage, a remote attacker can trigger a loop of OS-level dialogs (CWE-451). This results in a denial-of-service condition where the device becomes temporarily inoperable due to the persistent UI interference. The issue is resolved in version 26.3.0.

Affected products

  • LY Corporation LINE client for iOS versions prior to 26.3.0

Timeline

  • 2026-04-16: disclosed
  • 2026-04-16: advisory

References