CVE Vulnerabilities

CVE-2025-56139

The UI Performs the Wrong Action

Published: Sep 03, 2025 | Modified: Sep 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion.

Weakness

The UI performs the wrong action with respect to the user’s request.

Affected Software

Name Vendor Start Version End Version
Linkedin Linkedin 4.1.1087.2 (including) 4.1.1087.2 (including)

Potential Mitigations

References