CVE-2025-56139
MEDIUMDescription
LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
References
Frequently Asked Questions
What is CVE-2025-56139? +
How severe is CVE-2025-56139? +
What products are affected by CVE-2025-56139? +
How do I check if I'm vulnerable to CVE-2025-56139? +
Related Vulnerabilities
The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage …
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a …