What is CVE-2026-16881?
This vulnerability is a code injection flaw in LINE Android app versions prior to 26.7.2, caused by insufficient validation or sandboxing of external script content in profile templates. An attacker can execute arbitrary code by placing crafted content in a profile. Immediate update to version 26.7.2 or later is strongly recommended.
Azərbaycanca: Bu zəiflik LINE Android tətbiqinin 26.7.2-dən əvvəlki versiyalarında profil şablonlarında xarici skript kontentinin düzgün yoxlanılmaması nəticəsində yaranan kod inyeksiyası (code injection) boşluğudur. Təcavüzkar xüsusi hazırlanmış profillər vasitəsilə ixtiyari kod icra edə bilər. Tətbiqi dərhal 26.7.2 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of the LINE Android app are affected by CVE-2026-16881?
Versions prior to 26.7.2 are affected.
What should I do to protect against CVE-2026-16881?
You should immediately update the app to version 26.7.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.