律动BlockBeats
律动BlockBeats|Aug 28, 2026 00:14
[Ledger Discloses Vulnerability Details: Screen Display Parameters May Differ from Final Signature Parameters] BlockBeats News, August 28 — Yesterday, Ledger disclosed details of the LSB 023 security vulnerability on its official website. Certain applications built using the Ledger Secure SDK may still receive new APDU commands during user screen confirmation, causing the parameters displayed on the screen to differ from the final signature parameters. In scenarios where an attacker controls the APDU communication between the device and the host, the device may generate a signature for different parameters after the user confirms the operation shown on the screen. Ledger stated that the issue has been resolved through application-level verification and SDK-layer fixes, and Ledger Secure SDK v26.6.1 was released on August 21. Relevant applications have been rebuilt and published. Users need to update their applications via Ledger Live, as simply updating the device firmware is insufficient to fully address the issue. However, Ledger noted that there is currently no evidence indicating that this vulnerability has been exploited in practice. [Original Link]
+4
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads