VYPR
Unrated severityNVD Advisory· Published May 4, 2023· Updated Feb 12, 2025

CVE-2023-21506

CVE-2023-21506

Description

Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Out-of-bounds write in Samsung Blockchain Keystore bc_tui trustlet allows local arbitrary code execution via crafted BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command.

Vulnerability

An out-of-bounds write vulnerability exists in the bc_tui trustlet of Samsung Blockchain Keystore prior to version 1.3.12.1. The flaw is triggered by processing a crafted BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command, leading to a write beyond allocated memory boundaries.

Exploitation

An attacker requires local access to the device and the ability to send a malicious BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command to the bc_tui trustlet. No further authentication or user interaction is specified in the available references, though the command must reach the trustlet, typically requiring kernel-level or privileged access on the device.

Impact

Successful exploitation allows a local attacker to execute arbitrary code within the context of the bc_tui trustlet, which operates in the TrustZone secure world. This can lead to a full compromise of sensitive data managed by the Blockchain Keystore, such as cryptographic keys, and may allow further privilege escalation within the secure environment.

Mitigation

Samsung released the fix in version 1.3.12.1 of the Blockchain Keystore. Users should update to this version or later via Samsung's security update process, as described in the Samsung Mobile Security advisory published in May 2023 [1]. No workarounds are disclosed for unpatched devices.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.