Intel

AIKIDO-2025-10863

TrustWalletCore is vulnerable to Out-of-bounds Read

Out-of-bounds Read Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

38

Low Risk

This Affects:

SWIFTTrustWalletCore
3.1.34 - 4.4.2
Fixed in 4.4.3

TL;DR

Affected versions of this package are vulnerable to out-of-bounds memory access due to missing minimum-size checks in the parseAuthData function. When handling malformed or truncated authentication data, the parser may read beyond buffer boundaries, potentially leading to crashes, undefined behaviour, or further memory-corruption issues.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

TrustWalletCore is vulnerable to Out-of-bounds Read in versions 3.1.34 - 4.4.2.

How to fix this

Upgrade the TrustWalletCore library to a patch version.