VYPR
Unrated severityNVD Advisory· Published May 4, 2023· Updated Feb 12, 2025

CVE-2023-21510

CVE-2023-21510

Description

Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Out-of-bounds read in Samsung Blockchain Keystore BC_TUI trustlet allows local attacker to read arbitrary memory prior to version 1.3.12.1.

Vulnerability

An out-of-bounds read vulnerability exists in the bc_tui trustlet of the Samsung Blockchain Keystore when processing the BC_TUI_CMD_UPDATE_SCREEN command. The issue affects versions prior to 1.3.12.1. The flaw occurs in the trusted UI (TUI) component, which handles secure display of user interface elements during sensitive operations such as PIN entry or transaction confirmation. The vulnerability allows reading memory outside the intended buffer bounds, potentially leaking sensitive data.

Exploitation

Exploitation requires local access to the device and the ability to send crafted TUI commands to the bc_tui trustlet. The attacker must have already achieved user-level code execution on the Android system or be an application with appropriate permissions to interact with the Samsung Blockchain Keystore service. By sending a malicious BC_TUI_CMD_UPDATE_SCREEN command with manipulated parameters (e.g., buffer size or offset), the trustlet reads memory beyond the allocated region and returns the data to the caller. No additional user interaction is needed beyond launching the malicious application.

Impact

Successful exploitation leads to an out-of-bounds read, allowing the attacker to read arbitrary memory from the trustlet's address space. This can disclose sensitive information such as cryptographic keys, PIN codes, or other private data processed within the secure TEE (Trusted Execution Environment) environment. The impact is limited to information disclosure, as the vulnerability does not enable code execution or privilege escalation beyond the trustlet context.

Mitigation

The vulnerability is fixed in Samsung Blockchain Keystore version 1.3.12.1. Users should update the Trustlet to the latest version available via Samsung's software update mechanism (Settings > Software update). The fix was included in the May 2023 security maintenance release [1]. There are no known workarounds for unpatched versions.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.