Ledger Discloses SDK Command Interleaving Vulnerability; Patches Completed

iconTechFlow
Share
AI summary iconSummary
Ledger has disclosed a command interleaving vulnerability in its Secure SDK, affecting apps built on versions v26.6.0 and earlier. The flaw, which could allow a host to inject unauthorized APDU commands during user verification, was patched prior to the CFT regulatory review period. The issue—classified as a TOCTOU vulnerability—does not affect device firmware. Ledger stated there is no evidence of real-world exploitation. The company’s prompt response comes as risk-on assets are drawing renewed attention amid evolving regulatory frameworks.

According to Ledger’s official security advisory (LSB 023), the Ledger Secure SDK contains a command interleaving vulnerability: during the time a user is reviewing signature parameters on the device screen, the host may send a new APDU command, causing the actual signed content to differ from what is displayed on the screen—resulting in a classic "time-of-check to time-of-use" (TOCTOU) security flaw (CWE-362). This vulnerability was introduced in August 2025 and affects applications built using Ledger Secure SDK versions v26.6.0 and below; the device firmware itself is unaffected. Ledger states there is currently no evidence that this vulnerability has been exploited in the wild.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.