Out of LINE:QR Code to Wormable RCE in LINE Client
DAY 2
9:50-
10:30
In Japan, LINE has a penetration rate of over 75%, with more than 1 billion users worldwide, making it essential infrastructure for daily life, work, and social interaction. When an app at this scale contains vulnerabilities that let attackers take over a user’s phone, it is already out of LINE.
This talk presents my vulnerability research on the LINE Client, including a persistent Chat-DoS and an RCE vulnerability. I will demonstrate a full exploit chain from scanning a single QR Code to achieving root access, explain how Android-specific behaviors enable the chain, and show how LINE’s built-in features can escalate the impact into wormable RCE.
I will also share how I used AI agents to accelerate vulnerability research, where LLMs tend to make incorrect inferences, and what I learned from the disclosure process and vendor communication.
Join this session for the full story :)
-
Location :
-
Track 2(HALL A)
-
-
Category :
-
U25
-
-
Share :
Speakers
-
Lin Hong-Teng
林 紘騰
NTU CS Student / TRAPA Security Intern / Indie GameDev
Securing your LINE👊
- https://linktr.ee/flydragonw