Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fragment. Attackers can craft malicious miniscript policies that cause the device to derive and display incorrect receiving addresses, potentially leading to funds being sent to unintended addresses.
Metrics
Affected Vendors & Products
References
History
Wed, 20 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fragment. Attackers can craft malicious miniscript policies that cause the device to derive and display incorrect receiving addresses, potentially leading to funds being sent to unintended addresses. | |
| Title | Ledger Bitcoin App 2.1.0 Address Derivation Error via Miniscript | |
| Weaknesses | CWE-682 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-20T15:31:29.002Z
Reserved: 2026-05-20T13:07:44.334Z
Link: CVE-2023-7346
Updated: 2026-05-20T15:31:21.532Z
Status : Deferred
Published: 2026-05-20T16:16:23.770
Modified: 2026-05-20T17:33:05.830
Link: CVE-2023-7346
No data.
OpenCVE Enrichment
Updated: 2026-05-20T16:30:14Z