Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-3861

26
FAUCET Score

CVE-2026-3861 is a denial-of-service vulnerability affecting LINE client for iOS versions prior to 26.3.0. The flaw exists in the application's in-app browser functionality, where opening a specially crafted web page can trigger repeated OS-level dialogs that may render an iOS device temporarily inoperable. This vulnerability requires user interaction to be exploited, as victims must open a malicious webpage through the LINE client. The attack vector is network-based with low complexity, requiring only user interaction to trigger the issue. While the vulnerability cannot compromise confidentiality or integrity, it has a high availability impact due to the ability to temporarily disable device functionality. The CVSS score of 6.5 (Medium) reflects this profile, indicating moderate concern for user devices. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on any public exploit lists or security hotlists. The extremely low EPSS score of 0.00014 suggests minimal current threat activity. Organizations should prioritize patching to version 26.3.0 or later as part of routine security updates, particularly if users regularly interact with external web content through LINE's browser feature.

Impacted Technologies

VendorProductVersion(s)CPE
< 26.3.0CPE matchmatch criteria
cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:*

CVSS Data

CVSS version used by this source: 4.0

7.1HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 23rd percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

hackerone.com / reports/3422905
Permissions Required