Trezor Safe improper security check in on-device display
Fixed in: Trezor Safe 3, Safe 5, and Safe 7 (commit 70c9b0c)
details
- Finding IDs
- F-TREZOR-005
- CVE
- CVE-2026-65058
- Status
- patched
- CWE
- CWE-358
- Fixed in
- Trezor Safe 3, Safe 5, and Safe 7 (commit 70c9b0c)
- Recorded credit
- Oleh Konko / 1seal
- Note
- on-device confirmation in Ethereum sign_tx and sign_tx_eip1559 covered only the initial calldata chunk while the signature committed to the full streamed calldata. CISA published CSAF VA-26-202-02 through cisagov/CSAF PR #436; fixed in commit 70c9b0c.
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
F-TREZOR-005: Display / action mismatch. Confirmation covers the initial calldata chunk rather than the complete signed stream. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-TREZOR-005
Security area (1seal assessment): Semantics. Confirmation covers the initial calldata chunk rather than the complete signed stream. Reviewed 24 Sep 2026.