Ledger Patches Command Interleaving Vulnerability in Secure SDK
Ledger issued a security advisory (LSB 023) on August 28 regarding a command interleaving vulnerability in its Secure SDK. The flaw allows a host to send new APDU commands while a user is reviewing signature parameters on the device screen, leading to a Time-of-Check to Time-of-Use (TOCTOU) defect (CWE-362) where the signed content differs from what is displayed. The issue affects applications built on Ledger Secure SDK v26.6.0 and earlier, though device firmware remains secure. Ledger stated there is no evidence of exploitation.