Skip to main content
CVE Vulnerability Database

CVE-2026-3861: LINE iOS Client DoS Vulnerability

CVE-2026-3861 is a denial of service flaw in LINE client for iOS that causes repeated OS-level dialogs, rendering devices temporarily inoperable. This article covers technical details, affected versions, and mitigations.

Published:

CVE-2026-3861 Overview

LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs, potentially causing the iOS device to become temporarily inoperable. This vulnerability allows attackers to create denial of service conditions through user interface spoofing techniques that exploit the handling of dialog prompts within the LINE application's embedded browser component.

Critical Impact

Attackers can craft malicious web pages that, when opened in LINE's in-app browser, repeatedly trigger system-level dialogs causing the iOS device to become unresponsive and temporarily inoperable, resulting in denial of service for affected users.

Affected Products

  • LINE client for iOS versions prior to 26.3.0

Discovery Timeline

  • April 16, 2026 - CVE-2026-3861 published to NVD
  • April 16, 2026 - Last updated in NVD database

Technical Details for CVE-2026-3861

Vulnerability Analysis

This vulnerability is classified under CWE-451 (User Interface (UI) Misrepresentation of Critical Information), indicating that the LINE in-app browser fails to properly handle or limit the display of OS-level dialogs when processing malicious web content. The vulnerability allows network-based exploitation that requires user interaction to open a crafted web page.

The in-app browser component does not implement adequate rate limiting or dialog handling controls, allowing attackers to create web pages that programmatically trigger an excessive number of system dialogs. When a user navigates to such a malicious page through LINE's embedded browser, the rapid succession of dialogs overwhelms the iOS interface, rendering the device temporarily unusable.

Root Cause

The root cause stems from improper handling of dialog generation within LINE's in-app browser. The application does not enforce sufficient restrictions on how frequently or how many OS-level dialogs can be triggered by web content. This lack of dialog rate limiting allows malicious JavaScript or HTML constructs to continuously invoke system prompts, creating a denial of service condition through interface exhaustion.

Attack Vector

The attack is executed over the network and requires user interaction. An attacker would need to:

  1. Create a specially crafted web page containing code that triggers repeated OS-level dialogs
  2. Distribute the malicious link through messaging, social media, or other channels
  3. Convince a victim using LINE for iOS (versions prior to 26.3.0) to click the link within the LINE application
  4. Once the victim opens the link in LINE's in-app browser, the malicious page triggers a cascade of system dialogs

The attack exploits the trust users place in links shared through messaging platforms and the lack of proper dialog handling in the in-app browser component.

Detection Methods for CVE-2026-3861

Indicators of Compromise

  • Unusual web traffic patterns from LINE application accessing untrusted or unfamiliar domains
  • User reports of LINE application becoming unresponsive when opening links
  • iOS devices becoming temporarily inoperable after interacting with links in LINE
  • Unexpected system dialog activity associated with the LINE application

Detection Strategies

  • Monitor for abnormal patterns of dialog generation events associated with LINE's in-app browser
  • Implement URL reputation checking for links shared through messaging platforms
  • Review application logs for repeated system dialog invocations in rapid succession
  • Establish baseline behavior for LINE application resource usage and alert on deviations

Monitoring Recommendations

  • Deploy mobile device management (MDM) solutions to track application behavior anomalies
  • Implement network-level filtering for known malicious domains that may host exploit pages
  • Enable logging of in-app browser navigation events where possible
  • Monitor user support tickets for reports of application freezes or device lockups

How to Mitigate CVE-2026-3861

Immediate Actions Required

  • Update LINE client for iOS to version 26.3.0 or later immediately
  • Advise users to exercise caution when opening links from unknown sources within LINE
  • Consider temporarily using external browsers instead of LINE's in-app browser for untrusted links
  • Implement URL filtering at the network level to block known malicious domains

Patch Information

LINE Corporation has addressed this vulnerability in LINE client for iOS version 26.3.0. Users should update to this version or later through the Apple App Store. For additional technical details regarding this vulnerability, refer to the HackerOne Report #3422905.

Workarounds

  • Configure iOS settings to use the default Safari browser for external links instead of in-app browsers when possible
  • Train users to copy links and open them in Safari rather than using LINE's built-in browser for untrusted sources
  • Implement organizational policies requiring immediate updates to messaging applications
  • Use mobile threat defense solutions to detect and block malicious web content

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.