Ledger denied the existence of a critical vulnerability in its Ethereum application, stating that the issue had been discovered internally by its Donjon team and fixed before any public disclosure. The fix was deployed in version 1.22.2 on August 12, ten days before cybersecurity firm TestMachine published its findings. The vulnerability concerned the clear signing mechanism: a malicious website could submit a second command while the user was still viewing the first, potentially allowing unlimited token approvals without the user’s knowledge. CTO Charles Guillemet accused TestMachine of unnecessarily spreading FUD, criticizing the company for not following responsible disclosure protocols. Ledger recommends users verify that their Ethereum app is running version 1.22.2 or later.
Source: Read the original article

