LINE client for iOS vulnerable to universal cross-site scripting


The in-app browser of LINE client for iOS provided by LY Corporation contains a universal cross-site scripting vulnerability (CWE-79, CVE-2024-5739).

LY Corporation reported this vulnerability to JPCERT/CC to notify users of its solution through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 6.1 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Changed
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: None
Affected Products

LY Corporation
  • LINE Client for iOS versions prior to 14.9.0


If a user clicks a malicious iframe embedded in a website displayed on in-app browser, an arbitrary JavaScript may be executed from the iframe on the domain of the website.

[Update the Software]

Update the software to the latest version according to the information provided by the developer.

The developer has released version 14.9.0 that contains a fix for this vulnerability.

Vendor Information

LY Corporation
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [Other]
CVE (What is CVE?)

  1. CVE-2024-5739

  1. JVN : JVNVU#91384468
Revision History

  • [2024/06/24]
      Web page was published