Back to overview

CVE-2025-13476

CRITICAL
9.8
CVSS 3.1
Description
Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)

Metadata

CVE ID
CVE-2025-13476
State
PUBLISHED
Assigner
certcc
Reserved
2025-11-20 12:38 UTC
Published
2026-03-05 16:53 UTC
Last updated
2026-03-06 10:36 UTC
Vendor / Product
Rakuten Viber / Rakuten Viber Cloak - Android
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
Rakuten Viber Rakuten Viber Cloak - Android 25.7.2.0g < 27.2.0.0g
Rakuten Viber Rakuten Viber Cloak - Windows v25.6.0.0 < v27.3.0.0
Weakness (CWE)
CWESourceDescription
cna CWE-327 Use of a Broken or Risky Cryptographic Algorithm
cna CWE-693
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview