Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- CVE ASSIGNED: CVE-2025-52294
- CVE PUBLISHED STATE: PUBLISHED
- CVE LINK: https://nvd.nist.gov/vuln/detail/CVE-2025-52294
- CVE-2025-52294:
- Trust Wallet v8.45 (Android) fails to consistently enforce the in-app PIN when accessed via the recent apps screen, allowing a physically proximate attacker to bypass the lock screen and view wallet balance without authentication.
- Vulnerability Type: Insecure Permissions.
- Vendor: TrustWallet ([https://trustwallet.com/](https://trustwallet.com/)).
- Affected Product: [https://play.google.com/store/apps/details?id=com.wallet.crypto.trustapp](https://play.google.com/store/apps/details?id=com.wallet.crypto.trustapp) (v8.45).
- Attack Type: Physical.
- Attack Vector: Repeatedly open Trust Wallet via recent apps without entering PIN until lock screen bypasses.
- Reference POC: [https://x.com/Ravenzbb/status/1930337226115686676](https://x.com/Ravenzbb/status/1930337226115686676).
- Discoverer: Ishwar Kumar
Advertisement
Add Comment
Please, Sign In to add comment