Ledger Issues Urgent Update After Discovering New Signing Flaws
Crypto wallet maker Ledger has urged its Ethereum app users to update again after discovering two new signing flaws in its previous security release. The company released Ethereum app version 1.22.3 on August 25, which addresses vulnerabilities that could allow malicious actors to hide operations from device review or authorize token approvals in place of expected payments.
The update follows controversy over a separate Ethereum signing flaw reproduced by rival wallet maker OneKey. Ledger said OneKey demonstrated the bug against version 1.22.1 after the company had already fixed it in Ethereum app 1.22.2, released on August 13. However, two additional flaws, LSB-024 and LSB-025, remained until the release of 1.22.3.
LSB-024 affected how the Ethereum app processed arrays of operations during clear signing, while LSB-025 affected the token-payment path used by Ledger's Exchange application during swaps. Ledger said it found no evidence that either vulnerability was exploited in the wild.