ChainThink report: On August 28, according to an official announcement, Ledger disclosed a security vulnerability.
This vulnerability allows the host to inject new APDU commands before screen confirmation is complete, causing a mismatch between what is displayed on the device and the final signing parameters, potentially leading users to unknowingly sign altered paths, amounts, or addresses.
The vulnerability exists at the application SDK level; the device's operating system and firmware are not affected. The fix has been released with SDK version 26.6.1; users must update the relevant applications via Ledger Live, as upgrading the firmware alone will not resolve the issue.
Third-party developers have rebuilt the application using the new SDK.
