Regresar al centro de seguridad
Inability to cancel certain flows on pre-production firmware
Reportada en October 31, 2025
In a pre-production firmware for Trezor Safe 7, a user could enter a dialog where pressing Cancel did not actually cancel the flow. This issue occurred only in non-critical paths such as staking delegation or similar actions, not in fund-sending flows.
The issue was present only in a pre-production firmware that was available for small group of people directly after the launch of Safe 7. The fix was already included in the version released to the general public.
Vulnerabilidades solucionadas
Reportada por la comunidad. Investigada. Solucionada. Porque tu seguridad no es una opción.
- Donjon's Trezor Safe 3 evaluation12 de noviembre de 2024
- Missing confirmation in the ECDHSessionKey call26 de noviembre de 2023
- XSS in Trezor Connect legacy versions7 de febrero de 2023
- Insufficient field size check in Protobuf12 de julio de 2021
- XSS in Trezor Connect3 de agosto de 2020
- Missing path isolation check14 de julio de 2020