CVE-2025-66692
Published Jan 20, 2026A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Vendor/product archive
2 CVEs tagged to trustwallet / trust_wallet_core — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the entropy is 32 bits, as exploited in the wild in Dec…