BlockBeats report: On August 28, Ledger disclosed details of the LSB-023 security vulnerability on its official website. Applications built on the Ledger Secure SDK may still receive new APDU commands during user screen confirmation, resulting in a discrepancy between the parameters displayed on the screen and those used for the final signature. Under conditions where an attacker controls the APDU communication between the device and host, the device may generate a signature for different parameters after the user confirms the operation shown on the screen.
Ledger indicates that the issue has been resolved at the application-level checksum and SDK layer, and released Ledger Secure SDK v26.6.1 on August 21, with affected applications rebuilt and republished. Users must update their applications via Ledger Live; updating the device firmware alone is insufficient to resolve the issue. However, Ledger states there is currently no evidence that this vulnerability has been exploited in practice.

