CVE-2026-3861 is a denial-of-service vulnerability affecting LINE client for iOS versions prior to 26.3.0. The flaw exists in the application's in-app browser functionality, where opening a specially crafted web page can trigger repeated OS-level dialogs that may render an iOS device temporarily inoperable. This vulnerability requires user interaction to be exploited, as victims must open a malicious webpage through the LINE client. The attack vector is network-based with low complexity, requiring only user interaction to trigger the issue. While the vulnerability cannot compromise confidentiality or integrity, it has a high availability impact due to the ability to temporarily disable device functionality. The CVSS score of 6.5 (Medium) reflects this profile, indicating moderate concern for user devices. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on any public exploit lists or security hotlists. The extremely low EPSS score of 0.00014 suggests minimal current threat activity. Organizations should prioritize patching to version 26.3.0 or later as part of routine security updates, particularly if users regularly interact with external web content through LINE's browser feature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.3.0CPE matchmatch criteria | cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.