Ledger Ethereum App Flaw Exposes Users to Transaction Manipulation
A security flaw in Ledger's Ethereum app has been identified, affecting users who manage Ether and ERC-20 tokens on their hardware wallets. The issue lies in the Ethereum app's ability to be manipulated by a malicious web application while a transaction is being reviewed.
The attack requires that the user has granted permission for a website to communicate directly with their device through WebHID, and that they initiate a transaction on a manipulated or hijacked site. The researchers found that the pattern can be reproduced on a Ledger Flex, which suggests that other devices, such as the Nano X, Nano S Plus, Stax, and Apex, may also be vulnerable.
The security flaw was discovered by TestMachine and has been fixed in version 1.22.2 of the Ethereum app. Users can check their installed version by opening Ledger Live and looking for the Ethereum app's version number. If it is older than 1.22.2, users should update to the latest version.