CVE-2025-13476
Awaiting Analysis
Awaiting Analysis - Queue
Predictable TLS Fingerprint in Rakuten Viber Enables Traffic Blocking
Publication date: 2026-03-05
Last updated on: 2026-03-10
Assigner: CERT/CC
Description
Description
Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0βv25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| rakuten | viber | From 25.6.0 (inc) to 25.8.1.0 (inc) |
| rakuten | viber | 9.3.0.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-327 | The product uses a broken or risky cryptographic algorithm or protocol. |