CVE-2025-13476
EUVD-2025-20831405.03.2026, 19:15
Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| rakuten | viber | 25.6.0 ≤ 𝑥 ≤ 25.8.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration