PatchSiren

LY Corporation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH LY Corporation CVE published 2026-08-10

CVE-2026-13133

A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy. This vulnerability could potentially lead to arbitrary code execution, emphasizing the need for immediate attention [truncated]

HIGH LY Corporation CVE published 2026-08-04

CVE-2026-16881

A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. An attacker who can place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile. A server-side mitigat [truncated]

HIGH LY Corporation CVE published 2026-04-16

CVE-2026-3861

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-16T07:16:30.090Z and has not been modified since then. This HIGH severity vulnerability affects LINE client for iOS versions prior to 26.3.0, allowing crafted web pages to repeatedly trigger OS-level dialogs. Users should update to the latest version to mitigate this vulnerability. The in-app browse [truncated]