Rakuten Viber vulnerabilities
6 known vulnerabilities affecting rakuten/viber.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-12569P3HIGHCVSS 7.8fixed in 10.7.02019-06-03
CVE-2019-12569 [HIGH] CWE-426 CVE-2019-12569: A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbi
A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI. An attacker could exploit this vulnerability by convincing a targeted user to follow a malicious link. Successful exploitation could cause
nvd
CVE-2025-13476P3CRITICALCVSS 9.8≥ 25.6.0, ≤ 25.8.1.0v9.3.0.62026-03-05
CVE-2025-13476 [CRITICAL] CWE-327 CVE-2025-13476: Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and pre
Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)
nvd
CVE-2019-18800P3HIGHCVSS 8.8≤ 11.7.0.52019-11-06
CVE-2019-18800 [HIGH] CWE-311 CVE-2019-18800: Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victim's device contains cleartext information such as the device model and OS version, IMSI, and 20 bytes of udid in a binary format, whi
nvd
CVE-2020-14049P3HIGHCVSS 7.5fixed in 13.2.0.392020-06-22
CVE-2020-14049 [HIGH] CVE-2020-14049: Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious websit
Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication request, and either relay the request or capture the hash for offline password cracking. NOTE: this issue exists because of an incomplete fix for CVE-2019-12569.
nvd
CVE-2025-55996P4MEDIUMCVSS 6.3≤ 25.6.02025-09-12
CVE-2025-55996 [MEDIUM] CWE-79 CVE-2025-55996: Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/f
Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface
nvd
CVE-2018-3987P4MEDIUMCVSS 5.5v9.3.0.62020-02-13
CVE-2018-3987 [MEDIUM] CWE-200 CVE-2018-3987: An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Ra
An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats' functionality allows a user to delete all traces of a chat either by using a time trigger or by direct request. There is a bug in this functionality which leaves behind photos taken and shared on the se
nvd