云虫漏洞库

CVE-2026-16881 - A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile. A server-side mitigation has been deployed that also protects existing - 漏洞详情

漏洞编号:CVE-2026-16881

风险等级:未知

漏洞来源:CVE

CVE 编号:CVE-2026-16881

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:-

发布/更新时间:2026-08-04 / 2026-08-28

漏洞描述

A code injection vulnerability exists in the LINE Android app prior to version 26.7.2.

The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates.

As a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile.

A server-side mitigation has been deployed that also protects existing Android clients that have not been updated to version 26.7.2.

相关链接

« 返回首页