Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fragment. Attackers can craft malicious miniscript policies that cause the device to derive and display incorrect receiving addresses, potentially leading to funds being sent to unintended addresses.
Metrics
Affected Vendors & Products
References
History
Thu, 21 May 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ledger
Ledger ledger Bitcoin App |
|
| Vendors & Products |
Ledger
Ledger ledger Bitcoin App |
Wed, 20 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fragment. Attackers can craft malicious miniscript policies that cause the device to derive and display incorrect receiving addresses, potentially leading to funds being sent to unintended addresses. | |
| Title | Ledger Bitcoin App 2.1.0 Address Derivation Error via Miniscript | |
| Weaknesses | CWE-682 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-20T14:13:22.344Z
Updated: 2026-05-20T15:31:29.002Z
Reserved: 2026-05-20T13:07:44.334Z
Link: CVE-2023-7346
Updated: 2026-05-20T15:31:21.532Z
Status : Deferred
Published: 2026-05-20T16:16:23.770
Modified: 2026-05-20T17:33:05.830
Link: CVE-2023-7346
No data.
ReportizFlow