Bug Bounties

LINE

Powered by: 

Allows bounty splitting: 

Average time to first program response: 11

Average time to bounty awarded null: 

Average time to report resolved: 218

Handle line

Managed program: true

Name: LINE

Offers bounties: true

Offers swag: true

Response efficiency percentage: 97

Submission state: open

Url: https://hackerone.com/line

Website: https://line.me

In scope:

  • Asset identifier: *.line-apps.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier B_ Asset**
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: *.line.biz
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier B_ Asset**
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.line.me
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier B_ Asset** Previous standalone web domains such as live.line.me, music.line.me, news.line.me, store.line.me are now included in this wildcard. URLs that contain `nvapis.line.me` will be out of scope.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: *.line.naver.jp
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier B_ Asset**
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: 443904275
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** [Apple App Store](https://apps.apple.com/jp/app/line/id443904275) Please make sure you are testing the latest version. Only the latest version is considered in scope.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: 539883307
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** macOS: [Apple Mac App Store](https://apps.apple.com/id/app/line/id539883307) Please make sure you are testing the latest version. Only the latest version is considered in scope.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: 9wzdncrfj2g6
  • Asset type: WINDOWS_APP_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** [Microsoft Windows Store](https://www.microsoft.com/ja-jp/p/line/9wzdncrfj2g6) Please make sure you are testing the latest version. Only the latest version is considered in scope.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: Chrome Extension
  • Asset type: OTHER
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** https://chrome.google.com/webstore/detail/line/ophjlpahpchlmihnnnihgmmeilfjmjjc Please make sure you are testing the latest version. Only the latest version is considered in scope.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: LINE Messenger - Chat
  • Asset type: OTHER
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** Chat and Group Chat feature that can send texts, images, stickers and so on in LINE Messengers > Chats Tab and related servers. Supplementary services such as Album, Notes are also included.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: LINE Messenger - Keep
  • Asset type: OTHER
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** A storage service that lets you save photos, videos, text and files in LINE Messengers > Keep feature and related servers.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: LINE Messenger - News
  • Asset type: OTHER
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** News service in LINE Messengers > News Tab and related servers. Please note that this is available in Japan Only.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: LINE Messenger - OpenChat
  • Asset type: OTHER
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** Anonymous chat service in LINE Messengers > OpenChat and related servers.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: LINE Messenger - VOOM
  • Asset type: OTHER
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** Social media feature that can share contents in LINE Messengers > Voom Tab and related servers. The website (https://linevoom.line.me) is also included.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: LINE Messenger - VoIP
  • Asset type: OTHER
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** Voice and Video call service in LINE Messengers > Calls tab or call menu in a chat room and related servers.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: Other Assets
  • Asset type: OTHER
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: If you found a vulnerability in LINE's website or applications that are not explicitly listed in `Scopes`, it can still be submitted and the report will be triaged by LINE and evaluated on case by case basis. Depending on the outcome of the triage, it may not qualify for monetary reward, for example if it is not developed or maintained by LINE. Even for LINE domains, rewards may not be paid for assets developed/managed by 3rd party vendors (types of SaaS or solution products). * Any assets that are not managed by LINE and any LINE domains/sub-domains developed by third-party vendors will be carefully scrutinized. A bounty or reward may only be considered on a case-by-case basis and depending on the privacy and business impact
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: Windows Executable
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** https://desktop.line-scdn.net/win/new/LineInst.exe Please make sure you are testing the latest version. Only the latest version is considered in scope.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.linecorp.linelite
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** LINE Lite on the [Google Play Store](https://play.google.com/store/apps/details?id=com.linecorp.linelite)
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: jp.naver.line.android
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **_Tier A_ Asset** [Google Play Store](https://play.google.com/store/apps/details?id=jp.naver.line.android) Please make sure you are testing the latest version. Only the latest version is considered in scope.
  • Integrity requirements: 
  • Max severity: critical