๐Ÿ” CVE Alert

CVE-2026-16881

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile. A server-side mitigation has been deployed that also protects existing Android clients that have not been updated to version 26.7.2.

Vendor ly corporation
Product line client for android
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for ly corporation line client for android

Be the first to know when new unknown vulnerabilities affecting ly corporation line client for android are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

LY Corporation / LINE client for Android
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
line.github.io: https://line.github.io/security-advisory-blog/CVE-2026-16881/