CVE-2026-16881

LY Corporation · LINE client for Android

A code injection vulnerability exists in the LINE Android application, which could allow an attacker to execute arbitrary code via malicious input.

Executive summary

A critical code injection vulnerability in the LINE client for Android exposes users to potential arbitrary code execution.

Vulnerability

This is a code injection vulnerability (CWE-94) that allows unauthenticated attackers to execute arbitrary code on the host device. The attack vector requires user interaction (UI:P) to trigger the malicious payload.

Business impact

Successful exploitation of this vulnerability could lead to full compromise of the LINE application environment on the user device. Given the CVSS score of 8.7, this represents a high risk of data theft, unauthorized account access, and potential lateral movement on the mobile device, posing a significant threat to user privacy and corporate data security.

Remediation

Immediate Action: Update the LINE client for Android to version 26.7.2 or later via the official Google Play Store or authorized application repository.

Proactive Monitoring: Monitor device security logs for signs of unauthorized application behavior or unexpected privilege escalation attempts.

Compensating Controls: Ensure that mobile device management policies restrict the installation of applications from untrusted sources to limit the delivery of malicious payloads.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this flaw necessitates immediate action. All users and enterprise administrators managing mobile deployments should prioritize updating the LINE client to the patched version to eliminate the risk of code injection and subsequent system compromise.