Version 1.22.3 fixes two signature vulnerabilities left in the previous release
Ledger released version 1.22.3 of its Ethereum app on August 25 to fix two transaction-signing vulnerabilities. The update follows version 1.22.2, released on August 13, which had already fixed a separate flaw identified as LSB-023.
The first flaw, LSB-024, concerned the handling of operation arrays during clear signing. The app read the number of operations as a 16-bit value but stored the remaining count in an 8-bit field. In Ledger’s demonstration, an array of 257 operations reset the counter to one: the device displayed only the final operation, while the signature authorised the entire group.
According to Ledger, exploitation required a compromised host and an unusually large attacker-controlled operation array. The test was conducted on a private network fork, and the company said it had detected no user losses. Ledger’s records show that the fix was integrated on May 5, before version 1.22.2 was released.
The second vulnerability, LSB-025, affected the token-payment path used by the Ledger Exchange application during swaps. The app verified the token, amount and recipient without checking that the requested action was actually a payment. A malicious or compromised swap provider could replace a token approval using the same parameters. The approval does not transfer funds on its own and requires a subsequent transaction. Ledger recommends updating the Ethereum app through Ledger Live.





