BlockBeats News, August 28th. Yesterday, Ledger disclosed the details of the LSB 023 security vulnerability on its official website. Some applications built on the Ledger Secure SDK may still receive new APDU commands during the user's screen confirmation process, causing the parameters displayed on the screen to be inconsistent with the final signing parameters. In a scenario where an attacker controls the APDU communication between the device and the host, the device may generate a signature with different parameters after the user confirms the operation displayed on the screen.
Ledger has stated that it has fixed this issue through application-level validation and SDK layer, and released Ledger Secure SDK v26.6.1 on August 21st. The relevant applications have been rebuilt and released. Users need to update the applications via Ledger Live; updating only the device firmware is not sufficient to complete the fix. However, Ledger has mentioned that there is currently no evidence to suggest that this vulnerability has been exploited.

