LINE In-App Browser Vulnerable to Universal XSS Attacks
CVE-2024-5739
What is CVE-2024-5739?
The in-app browser of the LINE client for iOS prior to version 14.9.0 is susceptible to a Universal XSS (UXSS) vulnerability. This flaw enables attackers to execute arbitrary JavaScript within the top frame from an embedded iframe on any website viewed in the in-app browser. Typically initiated by tapping URLs in chat messages, this vulnerability allows for potential manipulation of displayed content and user session information if the victim inadvertently interacts with a malicious iframe. It is crucial for users of LINE client for iOS to update to version 14.9.0 or later to mitigate exposure to this risk. Other LINE client versions, such as those for Android, are not affected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
LINE client for iOS 14.0.0 < 14.9.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
