PT-2026-3650 · Trustwallet+1 · Trust Wallet Core+1

Published

2026-01-20

·

Updated

2026-01-20

·

CVE-2025-66692

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Binance - Trust Wallet Core versions prior to commit 5668c67
Description A buffer over-read in the PublicKey::verify() method allows attackers to cause a Denial of Service (DoS) by providing a crafted input. A buffer over-read occurs when a program reads data past the end of the intended buffer, which can lead to system crashes.
Recommendations Update to commit 5668c67 or a later version. As a temporary workaround, restrict the use of the PublicKey::verify() method to trusted inputs.

Exploit

Fix

Buffer Over-read

Weakness Enumeration

Related Identifiers

CVE-2025-66692

Affected Products

Trust Wallet Core
Wallet-Core