PT-2026-62107 · Trezor+1 · Safe 3+3

CVE-2026-65058

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Trezor Safe 3 (affected versions not specified) Trezor Safe 5 (affected versions not specified) Trezor Safe 7 (affected versions not specified)
Description A confirmation-binding flaw exists in the Ethereum sign tx and sign tx eip1559 flows. During contract interactions, the device confirms only the initial calldata chunk, whereas the signature commits to the full streamed calldata. This allows an attacker to present specific calldata to a victim and subsequently provide a different tail, altering the signed transaction.
Recommendations Update Trezor Safe 3 firmware to version 70c9b0c. Update Trezor Safe 5 firmware to version 70c9b0c. Update Trezor Safe 7 firmware to version 70c9b0c.

Exploit

Fix

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65058

Affected Products

Safe 3
Safe 5
Safe 7
Trezor-Firmware