Description
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a significant portion of network traffic, which could allow a network-adjacent attacker to intercept or modify encrypted communications.
INFO
Published Date :
2025-12-15T06:43:47.276Z
Last Modified :
2025-12-15T06:43:47.276Z
Source :
LY-Corporation
AFFECTED PRODUCTS
The following products are affected by CVE-2025-14022 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-14022.
| URL | Resource |
|---|---|
| https://hackerone.com/reports/2853445 |
|
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact