Ledger said on its website that it disclosed details of the LSB 023 security vulnerability yesterday. The issue affects some apps built with the Ledger Secure SDK, where new APDU commands could still be received while a user is confirming a transaction on screen. That could cause the parameters shown on the device display to differ from the parameters ultimately signed.
According to Ledger, if an attacker were able to control APDU communications between the device and the host, the device could generate a signature for different parameters even after the user approved the operation shown on screen. The company said it has fixed the issue through application-level checks and changes at the SDK layer.
Ledger also said it released Ledger Secure SDK v26.6.1 on Aug. 21, and affected applications have since been rebuilt and republished. Users need to update those apps through Ledger Live, as updating device firmware alone is not enough to fully address the issue. Ledger added that it has found no evidence that the vulnerability has been exploited in real-world attacks so far.
Ledger disclosed details of the LSB 023 security vulnerability on its official website yesterday. The company said some applications built on the Ledger Secure SDK could still receive new APDU commands while a user was confirming a transaction on the device screen, creating a mismatch between the parameters displayed and the parameters ultimately signed.
According to Ledger, if an attacker controlled APDU communications between the device and the host, the device could generate a signature for different parameters after the user approved the operation shown on screen.
Ledger said it has fixed the problem through application-level validation and changes at the SDK layer. It released Ledger Secure SDK v26.6.1 on Aug. 21, and the affected applications have been rebuilt and republished.
The company said users need to update applications through Ledger Live, and that updating device firmware alone is not sufficient to complete the fix. Ledger also said there is currently no evidence that the vulnerability has been exploited in practice.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.