Ledger discloses vulnerability details: screen display parameters may be inconsistent with final signature parameters
Yesterday, Ledger disclosed details of the LSB 023 security vulnerability on its official website. Some applications built on the Ledger Secure SDK may still receive new APDU commands during the user screen confirmation, leading to inconsistencies between the parameters displayed on the screen and the final signature parameters.
In cases where the attacker controls the APDU communication between the device and the host, after the user confirms the operation shown on the screen, the device may generate a signature with different parameters. Ledger stated that it has fixed the issue through application-level checks and the SDK layer, and released Ledger Secure SDK v26.6.1 on August 21. The relevant applications have been rebuilt and released. Users need to update the applications through Ledger Live; merely updating the device firmware is insufficient to complete the fix. However, Ledger claims there is currently no evidence that the vulnerability has been exploited.






