CVE-2026-16881
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile. A server-side mitigation has been deployed that also protects existing Android clients that have not been updated to version 26.7.2.
| Vendor | ly corporation |
| Product | line client for android |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for ly corporation line client for android
Be the first to know when new unknown vulnerabilities affecting ly corporation line client for android are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
LY Corporation / LINE client for Android
All versions affected