PT-2026-62107 · Trezor+1 · Safe 3+3
CVE-2026-65058
·
Published
2026-07-21
·
Updated
2026-07-21
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Trezor Safe 3 (affected versions not specified)
Trezor Safe 5 (affected versions not specified)
Trezor Safe 7 (affected versions not specified)
Description
A confirmation-binding flaw exists in the Ethereum
sign tx and sign tx eip1559 flows. During contract interactions, the device confirms only the initial calldata chunk, whereas the signature commits to the full streamed calldata. This allows an attacker to present specific calldata to a victim and subsequently provide a different tail, altering the signed transaction.Recommendations
Update Trezor Safe 3 firmware to version 70c9b0c.
Update Trezor Safe 5 firmware to version 70c9b0c.
Update Trezor Safe 7 firmware to version 70c9b0c.
Exploit
Fix
Improperly Implemented Security Check for Standard
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Safe 3
Safe 5
Safe 7
Trezor-Firmware