NONE · 0

CVE-2026-16881

A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embe...

Vulnerability Description

A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile. A server-side mitigation has been deployed that also protects existing Android clients that have not been updated to version 26.7.2.

References

FAQ

What is CVE-2026-16881?

CVE-2026-16881 is a documented vulnerability. A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embe...

How severe is CVE-2026-16881?

CVSS scoring is not yet available for CVE-2026-16881. Check NVD for updates.

Is there a patch for CVE-2026-16881?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.