
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13476 is a cryptographic weakness in Rakuten Viber's "Cloak" proxy mode that allows Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining the app's censorship circumvention capabilities. The flaw affects Viber for Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0, and was publicly disclosed on March 5, 2026, after the vendor was notified on August 14, 2025. The vulnerability was discovered by independent security researcher Oleksii Gaienko and coordinated through CERT/CC. It carries a CVSS v3.1 base score of 9.8 (Critical) as assigned in the NVD, though the practical impact is primarily a privacy/anonymity failure rather than a traditional remote code execution scenario (CERT/CC, Red Hat CVE).
The root cause is classified as CWE-327 (Use of a Broken or Risky Cryptographic Algorithm), specifically the use of a static and predictable TLS ClientHello fingerprint in Viber's Cloak proxy mode that lacks extension diversity. Cloak mode is designed to disguise proxy or VPN traffic as normal browser TLS traffic, but the rigid, non-randomized ClientHello structure makes it trivially distinguishable by DPI systems. An attacker or network operator positioned to inspect network traffic (e.g., an ISP or government censor) can passively fingerprint the TLS handshake without any active interaction with the client. No exploitation of cryptographic keys or session content is required — the fingerprint alone is sufficient to identify and block the traffic (CERT/CC, Red Hat CVE).
The primary impact is the complete defeat of Viber's Cloak mode censorship circumvention feature: DPI systems operated by network administrators, ISPs, or government censors can identify and block Viber proxy traffic with no indication to the user that their proxy protection has failed. Users in restrictive network environments who rely on Cloak mode to access Viber securely are exposed to traffic blocking and potential identification of their proxy usage. While this does not result in direct code execution or data exfiltration by a remote attacker, it undermines confidentiality and accessibility objectives for users in high-risk environments (CERT/CC, Red Hat CVE).
There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation as of the disclosure date. The vulnerability is passively exploitable by any network operator with DPI capabilities — no special tooling beyond standard network inspection infrastructure is required. The EPSS score is approximately 0.051% (very low probability of exploitation in the traditional sense), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (CERT/CC, Red Hat CVE).
Users should upgrade Rakuten Viber immediately: Android users should update to v27.2.0.0g or later, and Windows users should update to v27.3.0.0 or later, as these versions address the static TLS fingerprint issue. Windows users can enable automatic updates for Viber to ensure timely patching. No configuration-based workaround is available for the affected versions — updating is the only effective remediation (CERT/CC, Viber Download).
Security media covered the disclosure, with outlets such as SecurityOnline and CyberInsider highlighting the privacy implications for users in censorship-heavy environments. The Hacker News included the vulnerability in its weekly recap for the week of March 8, 2026. The CERT/CC credited independent researcher Oleksii Gaienko for the discovery and coordinated disclosure. No formal public statement from Rakuten Viber was included in the CERT/CC advisory at the time of publication (CERT/CC, The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."