5.3
CVE-2025-56139
- EPSS 0.31%
- Veröffentlicht 03.09.2025 00:00:00
- Zuletzt bearbeitet 08.09.2025 18:37:24
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.219 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-449 The UI Performs the Wrong Action
The UI performs the wrong action with respect to the user's request.
https://hdhrmi.blogspot.com/2025/07/aiman-al-hadhrami-linkedin-vulnerability.html
https://hdhrmi.blogspot.com/2025/09/link-preview-mismatch-cve-2025-56139.html