Top/Articles/LINE freezing your iPhone? Below 26.3.0 it is a known bug
unknown-cover-en-update

LINE freezing your iPhone? Below 26.3.0 it is a known bug

LINE for iPhone flaw (CVE-2026-3861): a crafted link fills the screen with pop-ups and briefly freezes the device. No data stolen. Update to 26.3.0 to fix.

NewsPublished July 13, 2026Last updated Aug. 19, 2026
Table of contents
Key takeaways

LINE for iPhone flaw (CVE-2026-3861): a crafted link fills the screen with pop-ups and briefly freezes the device. No data stolen. Update to 26.3.0 to fix.

You are using LINE on an iPhone, and the moment you open a link, confirmation pop-ups start piling up faster than you can dismiss them. The screen fills with them and nothing responds. There is one clear cause behind this symptom.

It is a known bug in versions of LINE for iOS earlier than 26.3.0. The tracking ID is CVE-2026-3861. The developer, LY Corporation, fixed it in April 2026, and moving to 26.3.0 or later stops it from happening. It is not the kind of flaw that leaks the contents of your chats or lets someone take over your account.

The flip side is just as important: if you are on 26.3.0 or later and LINE still locks up, this bug is not your cause. This article is written so you can make that call first. It walks through how to check your version, what to do if you are affected, and where to look if you are not.

The short version

  • If your LINE for iOS is earlier than 26.3.0, opening a crafted link makes confirmation dialogs appear endlessly until the device stops responding. It is a known bug, and updating fixes it.
  • 26.3.0 or later is not affected. The current App Store release as of August 2026 is 26.12.1, so anyone who updates normally passed this point long ago.
  • This bug cannot steal your chats, contacts, or account. If the phone locks up, quitting the app or restarting brings it back. There are no reports of it being used against anyone in the wild.

Start by checking your LINE version

Whether this applies to you comes down to a single question: is your version 26.3.0 or higher? Checking takes about thirty seconds.

Open LINE and tap the settings gear at the top right of the Home tab. Scroll down to "About LINE" and open it, and your current version is shown there.

Version shownAffected by this bug?What to do
Earlier than 26.3.0Yes
(can lock up)
Update in the App Store
26.3.0 or laterNo
(already fixed)
Look for another cause
Android versionNoNothing special

As of August 2026, the build the App Store ships for LINE is 26.12.1 (updated August 11, 2026). That is nine releases past 26.3.0, where the fix landed, so anyone with automatic updates turned on has almost certainly sailed past this bug without ever hearing about it.

The case to watch out for is an older iPhone. Current LINE requires iOS 18 or later, so devices on anything older cannot install the latest build. Do not assume "no update button means I must be current" — check the actual number using the steps above. If it is stuck below 26.3.0, you are affected. Note too that LY Corporation retires support for old releases over time; support for iOS versions below 14.6.3 has already ended (Japanese).

What is going on if you are below 26.3.0

CVE-2026-3861: confirmation dialogs that never stop

When you tap a link posted in a LINE chat, the page opens not in Safari but in a browser built into LINE itself — an in-app browser. It is the screen that lets you read a news story or a coupon without leaving the app.

A web page can embed instructions that call up other apps — "open LINE," "open Maps" — using a mechanism called a URL scheme. Normally, tapping one produces a single "Open this?" confirmation. In versions of LINE earlier than 26.3.0, however, there was no limit on how many times that confirmation could be raised.

A page built to abuse that can fire the confirmation dialog hundreds of times in a fraction of a second. Each one you dismiss is replaced by the next, and the whole iPhone stops responding. The advisory from JVN, the vulnerability database run by JPCERT/CC (JVNVU#94039788), describes it as opening a specially crafted web page causing dialogs to be displayed repeatedly, which may render the device temporarily inoperable.

ItemDetail
Tracking IDCVE-2026-3861
JVNVU#94039788
AffectedLINE for iPhone and iPad
earlier than 26.3.0
Fixed in26.3.0 and later
What happensscreen fills with dialogs
device temporarily unusable
Data theft / hijackNone
Severity7.1 (CVSS 4.0)
6.5 (CVSS 3.1)
both self-reported by the vendor
Exploitation in the wildNone reported
(as of August 19, 2026)
DeveloperLY Corporation

The fix is simply to update the app. Open the App Store on your iPhone, tap the account icon at the top right, and if LINE appears in the list, tap "Update." If it is not listed, search for LINE and check whether the button reads "Update" rather than "Open." Once the version reads 26.3.0 or higher, you are done.

To avoid running into the same thing again, the surest move is to leave automatic app updates turned on. Switch on Settings → App Store → App Updates on your iPhone and future fixes arrive without you having to do anything.

If you are on 26.3.0 or later and it still locks up

In that case, what you are seeing is not the bug described here. From 26.3.0 onward, the repeated-dialog behaviour itself is blocked. The freeze may look the same, but the cause lies elsewhere.

The thing to check is whether the pop-ups pile up the instant you open a link. The symptom of this particular bug is quite distinctive. A screen that freezes with no pop-ups at all, an app that crashes, general sluggishness, one specific chat that will not open — none of those are this.

For those cases, the first things to try are collected in LINE's official help page on troubleshooting problems and malfunctions (Japanese). The steps it lists are as follows.

Steps recommended by LINE's official help

  • Power the device off and back on (restart it)
  • Update LINE
  • Clear LINE's internal cache
  • Delete unneeded apps and data from the device (check that at least 2 GB is free)
  • Turn 4G / 5G / Wi-Fi off and back on again
  • Review or disable any web restrictions or content filtering service
  • (iPhone and iPad) Update the device OS, or use "Offload App"

If apps in general — not just LINE — are unstable, Apple's guidance for when an app does not respond or quits unexpectedly (Japanese) is also worth following: force-quit the app, restart the device, check for updates, and if none of that helps, delete the app and download it again. Bear in mind, though, that Apple itself warns data stored inside an app can be lost when you re-download it, so back up your chat history before trying that with LINE.

The one thing this article can state flatly is that on 26.3.0 or later, CVE-2026-3861 is not involved. Beyond that, it does not attempt to pin down which of the other possible causes is yours.

If your phone is frozen right now

First, to set your mind at ease: none of the steps below will erase your chat history or photos. Work through them calmly, in order.

Start by quitting the LINE app. Swipe slowly up from the bottom of the screen and pause with your finger held, and the open apps appear side by side. Flick the LINE card upward to close it. In most cases that is enough.

If the phone still will not respond, restart the iPhone. Press and hold the side button and a volume button together to bring up the power-off slider, then power down and back up. If the screen is completely unresponsive, use Apple's force-restart procedure (Japanese). After the restart, open LINE, check the version, and update on the spot if it is below 26.3.0.

If the link came from someone you do not recognise, do not open it a second time. To block the sender, use the menu at the top right of the chat room.

Who would use this, and why

If anyone were to actually use this bug, it would be someone who wants to make life difficult for a specific person: an opponent in a heated chat, a persistent nuisance, or someone blasting spam messages around. For an attacker after money or data there is nothing here to collect, so there is no payoff. The motive is closer to harassment than to crime for profit.

The method is crude: send a crafted link into a chat and, the moment the other person taps it, bury their screen in dialogs. From the receiving end, it feels like you opened an ordinary link the way you always do, and your iPhone abruptly stopped obeying you. In the sense that harm begins simply from opening a page, the entry point resembles that of iPhone spyware that infects a device just by being viewed — but only the entry point.

What you stand to lose is on an entirely different scale. Here it is "a few dozen seconds to a few minutes without a usable phone," and nothing more. For companies and organisations, it amounts to a temporary inconvenience on an employee's personal device rather than anything that damages internal systems. The bug has never appeared, through the August 18, 2026 edition, on the U.S. CISA catalogue of vulnerabilities known to be exploited in attacks (KEV). The assessment attached to it on NVD likewise records no confirmed exploitation, and within the public record there is no report of this bug ever being used against anyone.

A technical look

The root cause is that the in-app browser placed no ceiling on the number or frequency of URL-scheme confirmation dialogs it would display on a web page's request. JVN puts it as insufficient protection when handling arbitrary URL schemes.

The databases disagree on classification. JVN assigns CWE-400 (uncontrolled resource consumption), while NVD assigns CWE-451 (user interface misrepresentation of critical information). The first treats "being able to keep raising them" as the heart of the problem, the second treats "the screen no longer being able to show what it should." Either way, the outcome is identical.

Severity is 7.1 under CVSS 4.0 and 6.5 under CVSS 3.1. Both figures, however, were supplied by LY Corporation as the vendor; NVD has not published an independent assessment. The 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, where confidentiality (C) and integrity (I) are both N — no impact — and only availability (A) is High. That line-up shows a flaw dialled entirely toward "made unusable" rather than "stolen." UI:R means the user has to tap the link; nothing goes off on its own.

The issue was reported through the bug bounty platform HackerOne, and LY Corporation disclosed and fixed it in coordination with JPCERT/CC. The company publishes vulnerabilities in its own products on an ongoing basis via its security advisory blog. In-app browsers trade the freedom to invoke other apps for the obligation to build in brakes against exactly this kind of abuse — a point that applies to smartphone apps generally.

How the disclosure unfolded

This bug is often taken to have been "discovered in July 2026," which is not quite right. The vendor's official advisory and the fixed build both landed on April 16, 2026 (with a content revision on April 30), and JVN's July 13 advisory was a fresh notice to users in Japan roughly three months later. Japanese news coverage clustered in mid-July because it followed JVN's announcement, by which point the fixed version had long since been widely distributed.

← Swipe to navigate

Common questions

Q. Can this bug be used to steal my LINE chats or my account?

A. No. Nothing is stolen and no account is taken over. All that happens is a temporary freeze; chat history, contacts, photos and other data are untouched. In the severity breakdown, every category relating to information disclosure is rated as no impact.

Q. I have already updated. Could a link I opened in the past still be affecting me?

A. No. The bug only stacks dialogs in the moment; it is not the kind that plants anything on the device. Once you have updated, there is no need to worry about pages you opened earlier.

Q. Is LINE for Android affected?

A. Only the iPhone and iPad (iOS) version is affected. Android is not. If you follow how apps are managed on phones more broadly, the new restrictions on Android sideloading are worth watching too.

Q. What about LINE on PC, iPad, or Linux?

A. This affects the iOS app, and iPad counts as part of the iOS version. Environment topics such as how to run LINE on Linux are covered in separate articles.

Q. Is this still an ongoing danger?

A. If you have updated, the matter is closed. Four months on from the fix, there have been no revisions from JVN, no additional notices from the vendor, and no reports of exploitation. The only risk left is having an un-updated device on hand.

Bottom line

If you use LINE on an iPhone and the confirmation pop-ups will not stop the moment you open a link, leaving you unable to touch anything — start with your version. Below 26.3.0, the cause is a known bug tracked as CVE-2026-3861, and updating fixes it.

On 26.3.0 or later, this bug is not involved and the cause is something else. Either way, the only thing at stake is your time; your chats and your account are not in danger. For the long run, keep LINE at 26.3.0 or higher — which today means 26.12.1 in the App Store. That is the whole of it.

Sources

avatar-m-1

Makoto Horikawa

Backend Engineer / AWS / Django