CVE-2025-14022
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-14022 is an improper SSL/TLS certificate validation vulnerability in the LINE client for iOS that enables man-in-the-middle (MitM) attacks. The flaw originates from an integrated financial SDK bundled within the app, which interfered with the application's network processing and effectively disabled server certificate verification for a significant portion of network traffic. It affects LINE for iOS versions prior to 15.4.0, and was published on December 15, 2025, with LY Corporation as the assigner. The CVSS v3.1 base score is 6.8 (Medium) (Red Hat CVE, ENISA EUVD).

Technical details

The root cause is classified as CWE-295 (Improper Certificate Validation). The integrated financial SDK within the LINE iOS app overrode or interfered with the application's standard TLS certificate verification logic, causing the app to accept connections without properly validating server certificates for a significant portion of its network traffic. An attacker positioned on the same network segment (adjacent network) can exploit this without any privileges or user interaction by intercepting TLS-protected communications and presenting a rogue or self-signed certificate. The vulnerability was originally reported via HackerOne (report #2853445) (ENISA EUVD, HackerOne).

Impact

Successful exploitation allows a network-adjacent attacker to intercept and modify encrypted communications between the LINE iOS client and its servers, resulting in high confidentiality and high integrity impact. Sensitive user data transmitted through the app — including messages, authentication tokens, and financial information handled by the integrated SDK — could be exposed or tampered with. Availability is not directly impacted, but the interception of session credentials could enable account takeover and further unauthorized access (Red Hat CVE, ENISA EUVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14022 as of the available data. The EPSS score is approximately 0.02%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to be on the same network as the victim (e.g., a shared Wi-Fi network), which limits the attack surface but makes it realistic in public or untrusted network environments (Red Hat CVE, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify targets using the LINE iOS app (versions prior to 15.4.0) on a shared or public network (e.g., café Wi-Fi, corporate WLAN).
  2. Network Positioning: Position the attacker's device on the same network segment as the victim, enabling ARP spoofing or rogue access point attacks to intercept traffic.
  3. ARP Spoofing / Rogue AP Setup: Use tools such as arpspoof, ettercap, or a rogue Wi-Fi access point to redirect the victim's network traffic through the attacker's machine.
  4. TLS Interception: Deploy a TLS-intercepting proxy (e.g., mitmproxy, Burp Suite) with a self-signed or attacker-controlled certificate. Because the vulnerable LINE iOS app does not properly validate server certificates for affected traffic, the proxy's certificate is accepted without error.
  5. Traffic Capture and Modification: Capture plaintext HTTP/application-layer data from the intercepted TLS sessions, including messages, tokens, or financial SDK communications, and optionally modify responses in transit.
  6. Credential/Session Harvesting: Extract authentication tokens or session identifiers from the captured traffic for potential account takeover or further exploitation (ENISA EUVD, HackerOne).

Indicators of compromise

  • Network: Unexpected ARP replies associating the gateway MAC address with a different IP; traffic from LINE iOS devices routed through an intermediate host not matching the legitimate gateway.
  • Network: TLS handshakes from the LINE iOS app accepting certificates issued by unknown or self-signed certificate authorities.
  • Logs: Mobile device network logs showing TLS connections to LINE servers established via an unexpected intermediate IP address.
  • Process/Behavior: LINE app on iOS versions prior to 15.4.0 connecting over untrusted networks without certificate pinning errors or warnings.

Mitigation and workarounds

LY Corporation has addressed the vulnerability in LINE for iOS version 15.4.0 and later, which restores proper SSL/TLS certificate validation. Users should update the LINE app to version 15.4.0 or higher via the Apple App Store immediately. As a temporary workaround, users should avoid using the LINE app on untrusted or public Wi-Fi networks until the update is applied. No configuration-based workaround within the app itself is available (Red Hat CVE, ENISA EUVD).

Community reactions

The vulnerability was disclosed via HackerOne's coordinated disclosure program and received standard coverage from vulnerability tracking services. No notable researcher commentary, vendor blog posts, or significant social media discussion beyond automated CVE tracking feeds has been identified for this CVE (HackerOne).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management