CVE-2025-13476Disclosure(rakuten / viber)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch rakuten viber systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-327

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • viber

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-05); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
viber

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-05: 2Mentions · 2026-03-06: 1Mentions · 2026-03-09: 2Mentions · 2026-04-15: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-05: 2Technical Details · 2026-03-09: 203-0503-0603-0904-15
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-052
Disclosure2
2026-03-061
Disclosure1
2026-03-092
Disclosure1Patch1
2026-04-151
Disclosure1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    CERT/CC reveals a major privacy flaw (CVE-2025-13476) in Viber's Cloak mode, allowing network censors to easily identify and block proxy traffic. #Viber #CVE #CyberSecurity #PrivacyFlaw #Censorship #TLSFingerprinting #InfoSec #PatchAlert #AppSec https://securityonline.info/exposed-in-plain-sight-critical-privacy-flaw-defeats-vibers-anti-censorship-cloak-mode/

    Post summary

    CERT/CC has publicly disclosed a privacy flaw in Viber's Cloak mode that could let censors detect and block proxy traffic, but no PoC, exploit or patch details are provided.

    02031354
    10.6K followersView on X
  • CypherByte@cypherbyteio
    Disclosure

    Viber's 'Cloak mode' was supposed to hide activists and journalists from censorship surveillance. CVE-2025-13476 breaks it completely. People are visible to the exact tools they were trying to escape. https://www.cypherbyte.io/explained/viber-cloak-mode-flaw-exposes-users-censorship #CVE2025 #CyberSecurity #Viber #PrivacyFail https://t.co/1dsNFSuPjs

    Post summary

    The tweet announces that Viber’s Cloak mode flaw (CVE-2025-13476) exposes users to the tools they were avoiding, but it does not include a PoC, patch, or evidence of active exploitation.

    00000210
    6 followersView on X
  • 合同会社 セグメンテーション・フォルト公式@seg4_desk
    Patch

    #セキュリティ #IT Rakuten ViberのCloakモードにTLSハンドシェイク実装不備(CVE-2025-13476)が存在し、送信データの指紋からプロキシ利用が容易に識別され通信が遮断される恐れがある脆弱性で、AndroidとWindowsの特定バージョンが影響し更新で修正済み。 https://t.co/fxf5Fxm8ga

    Post summary

    The tweet discloses CVE‑2025‑13476 as a TLS handshake flaw in Rakuten Viber’s Cloak mode, noting it can expose proxy usage and that it has been patched through an update for specific Android and Windows versions.

    00000144
    1 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『The Rakuten Viber messaging app for Android V25.7.2.0g and Windows V25.6.0.0-V25.8.1.0, has a flaw in its TLS handshake implementation』 CVE-2025-13476 VU#772695 - A flawed TLS handshake implementation affects Viber Proxy in multiple platforms https://www.kb.cert.org/vuls/id/772695

    Post summary

    The text announces a TLS handshake flaw in Rakuten Viber’s Android and Windows apps, identified as CVE-2025-13476 and VU#772695, and directs readers to a CERT VULS page for details.

    00000477
    6.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-13476 - Rakuten Viber uses broken or risky cryptographic Algorithm Intel Report: https://ift.tt/gNC2RQy

    Post summary

    Brief advisory highlighting CVE‑2025‑13476’s impact on Rakuten Viber’s cryptographic algorithm, with no evidence of PoC, exploitation, or patch details.

    0000094
    343 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13476 Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, … https://www.cve.org/CVERecord?id=CVE-2025-13476

    Post summary

    The text announces CVE-2025-13476, detailing a predictable TLS ClientHello fingerprint vulnerability in Rakuten Viber's Cloak mode. No PoC, exploit, or mitigation is provided, indicating a straightforward disclosure.

    00000135
    56.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apprakutenviber-windows-
Apprakutenviber9.3.0.6android-

Explore more