CVE-2026-3861Disclosure(linecorp / line)

LOWCVSS 7.1 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch linecorp line systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-451

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • line

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Disclouser: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-07-15)
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
line

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-04-16: 2Mentions · 2026-07-15: 4Patch / Workaround · 2026-07-15: 2Technical Details · 2026-04-16: 2Technical Details · 2026-07-15: 204-1607-15
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
Disclouser
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-162
Disclosure2
2026-07-154
Disclosure1Disclouser1Patch2
Full discourse6 posts
  • ゆぅさん@YY20424277
    Disclosure

    「iOS版LINEにおけるサービス運用妨害(DoS)につながる脆弱性(CVE-2026-3861)」をボードに上げるなら1ページでどう書く? 背景/目的/効果の3軸で要約しました。 #セキュリティ #経営報告 ▶ 無料プログラム: https://www.intect-i.jp/local-program/?utm_source=sns&utm_medium=social&utm_campaign=local_program

    Post summary

    The post highlights a DoS vulnerability (CVE‑2026‑3861) in iOS LINE but offers only a high‑level description without detailed technical data, PoC, or patch information.

    0000061
    840 followersView on X
  • Yusuke Sakakura🍎携帯総合研究所@xeno_twit
    Patch

    Ping!!🗣️LINEに脆弱性、iPhoneが一時的に操作不能になるおそれ。最新版にアップデートを https://mobilelaby.com/blog-entry-line-ios-vulnerability-cve-2026-3861.html

    Post summary

    The blog post alerts users to a LINE vulnerability that could temporarily lock iPhones and recommends updating to the latest version to mitigate the risk.

    00000430
    3.2K followersView on X
  • 携帯総合研究所📱@mobilelabycom
    Patch

    更新通知:LINEに脆弱性、iPhoneが一時的に操作不能になるおそれ。最新版にアップデートを https://mobilelaby.com/blog-entry-line-ios-vulnerability-cve-2026-3861.html

    Post summary

    The post alerts users that a vulnerability in LINE could temporarily disable iPhones and advises updating to the latest version. No exploit details or active exploitation reports are mentioned.

    00000326
    517 followersView on X
  • ゆぅさん@YY20424277
    Disclouser

    【3軸解説】「iOS版LINEにおけるサービス運用妨害(DoS)につながる脆弱性(CVE-2026-3861)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post delivers a high‑level analysis of CVE‑2026‑3861, highlighting its DoS impact on iOS LINE, without providing PoC, exploit, patch, or false‑positive information.

    0000060
    840 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3861 Denial of Service in LINE iOS Client Prior to 26.3.0 via Crafted Web Page https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3861

    Post summary

    The text announces a new DoS vulnerability (CVE-2026-3861) in LINE iOS clients before version 26.3.0 that can be triggered via a crafted web page.

    0000034
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3861 LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs, po… https://www.cve.org/CVERecord?id=CVE-2026-3861

    Post summary

    The excerpt provides a brief disclosure of CVE‑2026‑3861, noting an iOS LINE client flaw that can trigger repeated OS dialogs via crafted web pages, but offers no PoC, exploit code, or active exploitation evidence.

    0000054
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinecorpline-iphone_os-

Explore more