Rakuten's vulnerability footprint centers on a diverse consumer-facing portfolio spanning messaging, e-commerce, and connectivity services, with a modest disclosure history concentrated around products such as Viber, Casa, Ichiba, Rakuma, and WiFi Pocket. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through durable weakness classes including cleartext transmission of sensitive data, improper authentication and authorization mechanisms, and exposure of sensitive information—patterns characteristic of applications handling user credentials and personal data. Defenders tracking this vendor should focus on mobile and cloud-connected services where authentication and data-protection issues carry elevated user-privacy impact; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rakuten over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13476CRITICAL Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep | Mar 5, 2026 | 9.8 | 32 | NO | NO |
CVE-2019-12569HIGH A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search | Jun 3, 2019 | 7.8 | 32 | NO | NO |
CVE-2022-29525CRITICAL Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbi | Jun 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-18800HIGH Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP d | Nov 6, 2019 | 8.8 | 28 | NO | NO |
CVE-2022-26834HIGH Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the produc | Jun 13, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-14049HIGH Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM | Jun 22, 2020 | 7.5 | 24 | NO | NO |
CVE-2019-6024MEDIUM Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication informati | Dec 26, 2019 | 6.5 | 22 | NO | NO |
CVE-2025-55996MEDIUM Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface | Sep 12, 2025 | 6.3 | 21 | NO | NO |
CVE-2024-41918MEDIUM 'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. A | Aug 29, 2024 | 6.1 | 19 | NO | NO |
CVE-2022-28704HIGH Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operati | Jun 13, 2022 | 7.2 | 19 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rakuten.
Media articles that mention a CVE ID that affects a product developed by Rakuten — matched by CVE ID, not by vendor name.