Ledger Fixes Critical Ethereum App Bug Allowing Malicious Transactions
Financial security firm Ledger has released an update to its Ethereum app after discovering a critical bug that could allow malicious actors to sign transactions without users' knowledge. The vulnerability, identified by security researchers at TestMachine, allowed a dApp or connected host with WebHID access to initiate a second signing command while a transaction was still under review.
According to Ledger's code history, the update fixes two defects: one that could allow new signing commands to tear down an active review before returning an error, and another that previously signed approval callbacks without confirming the app remained in the expected signing state.
The patched version, 1.22.2, closes this path by refusing a new signing session during an active review and rejecting an approval callback when the state no longer matches. This fix is applicable to Ledger Flex as well as other models including Nano X, Nano S Plus, Stax, and Apex.
TestMachine validated the attack on Ledger Flex and asserted that shared code extended the issue to multiple models. While Ledger has released a patch, it's essential for users to update their Ethereum app to the latest version to prevent potential security risks.