Ledger patched an Ethereum app bug that could show one transaction and sign another
Ledger customers ought to replace the Ethereum app to model 1.22.2 after official code adjustments confirmed that a malicious dApp or different linked host could begin a second signing command whereas a transaction was nonetheless underneath overview.
In the trail described by safety firm TestMachine, urgent approve could return a signature for substituted information as an alternative of the transaction proven on the system.
TestMachine said on Aug. 22 that the assault required a dApp with WebHID entry. The group mentioned a second command could change the transaction held in reminiscence with out opening a brand new overview, leaving the unique particulars on display screen whereas the system signed the alternative.
It mentioned the conduct was validated on Ledger Flex.
Ledger’s code historical past exhibits one official fix commit saying new signing instructions could tear down an lively overview earlier than returning an error. Another added state checks as a result of approval callbacks beforehand signed with out confirming that the app remained within the anticipated signing state.
Version 1.22.2 closes that documented path by refusing a brand new signing session throughout an lively overview and rejecting an approval callback when the state now not matches. The reviewed sources set up a code-level repair for these entry and callback defects.

TestMachine asserted that shared code prolonged the difficulty to Nano X, Nano S Plus, Stax, and Apex, and the tagged app manifest lists these fashions alongside Flex as construct targets.
Ledger’s release comparison begins from model 1.22.1, whereas the earliest affected app launch stays undisclosed.
Ledger’s changelog dates 1.22.2 to Aug. 12, GitHub exhibits the signed tag on Aug. 13, and TestMachine mentioned on Aug. 22 that the repair was not but launched.
Ledger CTO Charles Guillemet mentioned on Aug. 23 that Ledger Donjon had found a bug in “sure clear signing flows” and deployed the repair about two weeks earlier. The sources go away open whether or not TestMachine was referring to distribution by way of Ledger Wallet.
Guillemet mentioned Donjon discovered the bug earlier than TestMachine contacted Ledger’s bounty program, whereas TestMachine mentioned its Azimuth system discovered the difficulty and that it shared and verified the discovering with Ledger.
Users ought to verify that Ethereum app 1.22.2 is put in. Guillemet additionally suggested retaining system firmware, apps, and shopper software program present, though the general public sources give no firmware minimal particular to this flaw.
They report no confirmed in-the-wild exploitation, misplaced funds, or private-key extraction.
The concern is separate from the native Zilliqa Ledger app flaw involving Schnorr nonce leakage and the 2023 Connect Kit compromise, which concerned a malicious JavaScript library and reported losses.
The put up Ledger patched an Ethereum app bug that could show one transaction and sign another appeared first on CryptoSlate.
