
Public writeup for CVE-2025-55996 (Viber Desktop HTML Injection)
CVE: CVE-2025-55996
Discoverer: Thaw Khant (Cycbake)
Product: Viber Desktop
Affected: Viber Desktop 25.6.0 (and possibly earlier)
Viber Desktop's deep-link handler (viber://forward?text=) can render unsanitized HTML supplied in the text parameter inside the message compose/forward interface. While script execution appears restricted by the client, attacker-controlled external resources (e.g., images) can be loaded, enabling user tracking and UI manipulation that may facilitate phishing and privacy leakage.
Reproduction steps are intentionally redacted from this public writeup to avoid mass exploitation. A minimal repro was provided to vendor and MITRE at the time of reporting.
text parameter as plain text; do not render HTML by default.This public writeup intentionally omits exploit-level details. If you are a vendor or security contact requiring technical details for remediation, please contact the discoverer at the address above.