Loading...
Ledger has disclosed details of a LSB 023 security vulnerability, where some applications built on the Ledger Secure SDK can still receive APDU instructions during screen confirmation, resulting in inconsistencies between screen display parameters and final signature parameters. Ledger has released the Ledger Secure SDK v26.6.1 and rebuilt related applications. Users need to update their applications through Ledger Live. Currently, there is no evidence to suggest that this vulnerability has been actually exploited.