VYPR

trezor-firmware

by Trezor

CVEs (1)

  • CVE-2026-65058MedJul 21, 2026
    risk 0.00cvss 5.3epss 0.00

    Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker…