Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 10 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rakuten
Rakuten viber |
|
| Weaknesses | CWE-327 | |
| CPEs | cpe:2.3:a:rakuten:viber:*:*:*:*:*:windows:*:* cpe:2.3:a:rakuten:viber:9.3.0.6:25.7.2.0g:*:*:*:android:*:* |
|
| Vendors & Products |
Rakuten
Rakuten viber |
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rakuten Viber
Rakuten Viber rakuten Viber Cloak - Android Rakuten Viber rakuten Viber Cloak - Windows |
|
| Vendors & Products |
Rakuten Viber
Rakuten Viber rakuten Viber Cloak - Android Rakuten Viber rakuten Viber Cloak - Windows |
Fri, 06 Mar 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 05 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 05 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327) | |
| Title | Rakuten Viber uses broken or risky cryptographic Algorithm | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-03-06T10:36:09.154Z
Reserved: 2025-11-20T12:38:19.605Z
Link: CVE-2025-13476
Updated: 2026-03-05T18:35:24.559Z
Status : Analyzed
Published: 2026-03-05T19:15:58.283
Modified: 2026-03-10T19:49:55.930
Link: CVE-2025-13476
No data.
OpenCVE Enrichment
Updated: 2026-03-06T15:01:33Z