CVE-2025-13476 Details
Description
Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)
A vulnerability exists in the Rakuten Viber messaging application for Android version 25.7.2.0g and Windows versions 25.6.0.0 through 25.8.1.0. When Cloak mode is enabled, the application uses a static and easily recognizable TLS ClientHello fingerprint that lacks diversity in extensions. This flaw allows Deep Packet Inspection (DPI) systems to easily detect and block proxy traffic, thereby undermining efforts to bypass censorship. As a result, users may experience disruptions in service.
Users on Windows should upgrade to version 27.3.0.0 or later, while Android users should upgrade to version 27.2.0.0g or later. Windows users can enable automatic updates for Viber to ensure they receive the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/772695 | CVE | Third Party Advisory |
| https://www.viber.com/en/download/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rakuten viber | >= 25.6.0, <= 25.8.1.0 9.3.0.6 25.7.2.0g |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 10, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2026 | New CVE Received | [email protected] |
| Mar 5, 2026 | CVE Modified | CVE |