Ledger says LSB 023 flaw could cause signed parameters to differ from on-screen details

Ledger says LSB 023 flaw could cause signed parameters to differ from on-screen details

N
News Editor
2026-08-28 00:13:26
Ledger disclosed details of security issue LSB 023 on its website, saying some applications built with the Ledger Secure SDK could still receive new APDU commands while a user was reviewing a transaction on the device screen. In that scenario, the parameters shown during on-screen confirmation might not match the parameters ultimately signed by the device. Ledger said the risk would arise if an attacker controlled APDU communications between the device and the host. A user could approve the operation displayed on screen, yet the device could generate a signature for different parameters. The company said it has fixed the issue through application-level checks and changes at the SDK layer, and released Ledger Secure SDK v26.6.1 on Aug. 21. Affected applications have been rebuilt and republished. Ledger added that users need to update applications through Ledger Live, and that updating device firmware alone is not enough to complete the fix. The company also said there is currently no evidence that the flaw has been exploited in the wild.

Ledger disclosed details of security issue LSB 023 on its website on Aug. 28, according to BlockBeats.

The company said some applications built on the Ledger Secure SDK could still receive new APDU commands while users were confirming actions on the device screen. That could cause the parameters shown on screen to differ from the parameters ultimately signed.

If an attacker controlled APDU communications between the device and the host, a user could approve the operation displayed on the screen, while the device might generate a signature for different parameters.

Ledger said it has addressed the issue with application-level validation and an SDK-layer fix. It released Ledger Secure SDK v26.6.1 on Aug. 21, and the related applications have already been rebuilt and republished.

The company said users need to update the affected applications through Ledger Live. Updating device firmware alone is not sufficient to complete the fix.

Ledger also said it currently has no evidence that the vulnerability has been exploited in real-world attacks.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
30

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.