2026/08/25 - 3.12.0 Vulnerability Incident FAQ
Q: What was the identified vulnerability?
A vulnerability was identified in the Vivi Windows Client App, version 3.12.0. During installation, the app's installer adds a firewall rule that is intended to be tied to the Vivi Client process name. Due to a bug, this association was not correctly applied, meaning the firewall rule was not scoped to the process as designed.
This fix is listed in the 3.12.1 release notes as: "Fixed a security vulnerability with the Vivi Windows Installer."
Q: What version/s of Vivi are affected by this vulnerability?
The vulnerability affects the Windows Vivi App running version 3.12.0 on intel and AMD based devices.
Windows devices running on ARM processors are not affected.
Box firmware, the Vivi Receiver App, and the Vivi Display App are not affected.
The Vivi Client App on macOS, Android, Linux or ChromeOS are not affected.
Versions 3.10.5 and earlier are not affected.
Q: What steps should be taken on affected devices?
Customers should update to Windows Client App version 3.12.1, which includes a fix for the vulnerability. Alternatively, as versions 3.10.5 and earlier are not affected, downgrading is also an option.
Q: Where can I download the updated Windows Client App (v3.12.1)?
The Vivi Windows Client App version 3.12.1 is available for download from Vivi's official downloads page: https://www.vivi.io/downloads/.
Q: What is the risk if the patch is not applied?
If the patch is not applied, the firewall rule may not restrict access as intended, which could allow other applications or devices or processes on the same Windows device to make use of the network path the rule was meant to protect.