CVE Database
/

CVE-2025-13476

Back to search

CVE-2025-13476

Published: Mar 5, 2026

Modified: Mar 6, 2026

PUBLISHED

Description

Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)

VendorProductVersions

Rakuten Viber

Rakuten Viber Cloak - Android

affected
25.7.2.0g - < 27.2.0.0g

Rakuten Viber

Rakuten Viber Cloak - Windows

affected
v25.6.0.0 - < v27.3.0.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now