CVE-2025-13476: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-13476 is a cryptographic weakness in Rakuten Viber's "Cloak" proxy mode that allows Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining the app's censorship circumvention capabilities. The flaw affects Viber for Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0, and was publicly disclosed on March 5, 2026, after the vendor was notified on August 14, 2025. The vulnerability was discovered by independent security researcher Oleksii Gaienko and coordinated through CERT/CC. It carries a CVSS v3.1 base score of 9.8 (Critical) as assigned in the NVD, though the practical impact is primarily a privacy/anonymity failure rather than a traditional remote code execution scenario (CERT/CC, Red Hat CVE).

Technical details

The root cause is classified as CWE-327 (Use of a Broken or Risky Cryptographic Algorithm), specifically the use of a static and predictable TLS ClientHello fingerprint in Viber's Cloak proxy mode that lacks extension diversity. Cloak mode is designed to disguise proxy or VPN traffic as normal browser TLS traffic, but the rigid, non-randomized ClientHello structure makes it trivially distinguishable by DPI systems. An attacker or network operator positioned to inspect network traffic (e.g., an ISP or government censor) can passively fingerprint the TLS handshake without any active interaction with the client. No exploitation of cryptographic keys or session content is required — the fingerprint alone is sufficient to identify and block the traffic (CERT/CC, Red Hat CVE).

Impact

The primary impact is the complete defeat of Viber's Cloak mode censorship circumvention feature: DPI systems operated by network administrators, ISPs, or government censors can identify and block Viber proxy traffic with no indication to the user that their proxy protection has failed. Users in restrictive network environments who rely on Cloak mode to access Viber securely are exposed to traffic blocking and potential identification of their proxy usage. While this does not result in direct code execution or data exfiltration by a remote attacker, it undermines confidentiality and accessibility objectives for users in high-risk environments (CERT/CC, Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation as of the disclosure date. The vulnerability is passively exploitable by any network operator with DPI capabilities — no special tooling beyond standard network inspection infrastructure is required. The EPSS score is approximately 0.051% (very low probability of exploitation in the traditional sense), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (CERT/CC, Red Hat CVE).

Exploitation steps

  1. Network Positioning: An attacker or network operator deploys DPI hardware or software (e.g., commercial DPI appliances, nDPI, or similar tools) at a network chokepoint such as an ISP gateway, enterprise firewall, or national internet exchange.
  2. Traffic Capture: Intercept outbound TLS traffic from devices running Viber with Cloak mode enabled (Android v25.7.2.0g or Windows v25.6.0.0–v25.8.1.0).
  3. Fingerprint Matching: Analyze the TLS ClientHello messages in captured traffic. The static, non-randomized extension set and structure of Viber's Cloak mode ClientHello produces a consistent, identifiable fingerprint (e.g., via JA3 or similar TLS fingerprinting methods) that does not match legitimate browser TLS profiles.
  4. Traffic Blocking: Configure DPI rules to drop or reset connections matching the identified Viber Cloak fingerprint, effectively blocking the proxy traffic and defeating censorship circumvention for affected users — with no warning displayed to the user (CERT/CC).

Indicators of compromise

  • Network: Outbound TLS connections from Viber clients (Android v25.7.2.0g or Windows v25.6.0.0–v25.8.1.0) with a static, non-diverse ClientHello fingerprint detectable via JA3 or similar TLS fingerprinting tools; repeated TCP RST or connection drops to Viber proxy endpoints suggesting active DPI blocking.
  • Logs: Network flow logs showing consistent connection failures or resets to Viber proxy server IPs from affected client versions; absence of successful proxy handshake completions despite Cloak mode being enabled.
  • Application Behavior: Users on affected versions experiencing Cloak mode silently failing to bypass network restrictions with no in-app error or warning (CERT/CC).

Mitigation and workarounds

Users should upgrade Rakuten Viber immediately: Android users should update to v27.2.0.0g or later, and Windows users should update to v27.3.0.0 or later, as these versions address the static TLS fingerprint issue. Windows users can enable automatic updates for Viber to ensure timely patching. No configuration-based workaround is available for the affected versions — updating is the only effective remediation (CERT/CC, Viber Download).

Community reactions

Security media covered the disclosure, with outlets such as SecurityOnline and CyberInsider highlighting the privacy implications for users in censorship-heavy environments. The Hacker News included the vulnerability in its weekly recap for the week of March 8, 2026. The CERT/CC credited independent researcher Oleksii Gaienko for the discovery and coordinated disclosure. No formal public statement from Rakuten Viber was included in the CERT/CC advisory at the time of publication (CERT/CC, The Hacker News).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management