Ledger released Ethereum app 1.22.3 on August 25 to patch two signing flaws that remained in version 1.22.2, published thirteen days earlier. The first vulnerability, LSB-024, allowed a compromised host to hide operations from device review by exploiting a counter overflow when processing arrays containing 257 operations or more. The second, LSB-025, enabled a malicious swap provider to substitute a token approval for a payment without an additional device prompt. No evidence of exploitation was found. The irony is that fixes for both flaws had been merged into the codebase in May, months before their omission from version 1.22.2, with Ledger providing no explanation for the oversight.
Source: Read the original article

