Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-55996 PoC — Rakuten Viber Desktop 安全漏洞

Source
Associated Vulnerability
Title: Rakuten Viber Desktop 安全漏洞 (CVE-2025-55996)
Description:Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface
Description
Public writeup for CVE-2025-55996 (Viber Desktop HTML Injection)
Readme
# Viber Desktop — HTML Injection (CVE-2025-55996)

**CVE:** CVE-2025-55996  
**Discoverer:** Thaw Khant (Cycbake)  
**Product:** Viber Desktop  
**Affected:** Viber Desktop 25.6.0 (and possibly earlier)  

## Summary
Viber Desktop's deep-link handler (`viber://forward?text=`) can render unsanitized HTML supplied in the `text` parameter inside the message compose/forward interface. While script execution appears restricted by the client, attacker-controlled external resources (e.g., images) can be loaded, enabling user tracking and UI manipulation that may facilitate phishing and privacy leakage.

## Impact
- Remote image/resource loading from attacker-controlled domains (IP/meta leakage).
- Message UI manipulation (misleading text/graphics) enabling social engineering.
- Can be chained with other issues for greater impact.

## Reproduction (redacted)
Reproduction steps are intentionally redacted from this public writeup to avoid mass exploitation. A minimal repro was provided to vendor and MITRE at the time of reporting.

## Mitigation / Recommended fix
- Treat the `text` parameter as plain text; do not render HTML by default.
- Properly escape/encode user-supplied input before rendering in the client.
- Block or proxy external resource loading in forwarded messages (strip remote resource requests or force them to pass via a sanitizing proxy).


## Notes
This public writeup intentionally omits exploit-level details. If you are a vendor or security contact requiring technical details for remediation, please contact the discoverer at the address above.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →