LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android |
|
Vendors & Products |
Google
Google android |
Wed, 03 Sep 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-449 | |
Metrics |
cvssV3_1
|
Wed, 03 Sep 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-09-03T00:00:00.000Z
Updated: 2025-09-03T20:16:03.564Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56139

No data.

Status : Awaiting Analysis
Published: 2025-09-03T20:15:34.680
Modified: 2025-09-04T15:35:29.497
Link: CVE-2025-56139

No data.