header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Ledger Discloses Vulnerability Details: Screen Displayed Parameters Could Differ from Final Signature Parameters

BlockBeats News, August 28th. Yesterday, Ledger disclosed the details of the LSB 023 security vulnerability on its official website. Some applications built on the Ledger Secure SDK may still receive new APDU commands during the user's screen confirmation process, causing the parameters displayed on the screen to be inconsistent with the final signing parameters. In a scenario where an attacker controls the APDU communication between the device and the host, the device may generate a signature with different parameters after the user confirms the operation displayed on the screen.


Ledger has stated that it has fixed this issue through application-level validation and SDK layer, and released Ledger Secure SDK v26.6.1 on August 21st. The relevant applications have been rebuilt and released. Users need to update the applications via Ledger Live; updating only the device firmware is not sufficient to complete the fix. However, Ledger has mentioned that there is currently no evidence to suggest that this vulnerability has been exploited.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish