Vulnerability Description
A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trustwallet | Trust Wallet Core | < 4.4.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/inkman97/b791189338f73b758c31a7db3cd50c2dExploitThird Party Advisory
- https://github.com/trustwallet/wallet-core/commit/5668c67Patch
FAQ
What is CVE-2025-66692?
CVE-2025-66692 is a vulnerability with a CVSS score of 7.5 (HIGH). A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input.
How severe is CVE-2025-66692?
CVE-2025-66692 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-66692?
Check the references section above for vendor advisories and patch information. Affected products include: Trustwallet Trust Wallet Core.