CVE-2025-13476 - CVE House
Back to Database
Status published Unknown CVE-2025-13476

Rakuten Viber uses broken or risky cryptographic Algorithm

Vulnerability Description

Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13476

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Rakuten Viber

View all reports →

Affected Software

Rakuten Viber Cloak - Android, Rakuten Viber Cloak - Windows
Vulnerable Versions:
25.7.2.0g, v25.6.0.0

Timeline

Official Publish: March 5th, 2026
Last Modified: March 6th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.