Retour au portail de sécurité
Inability to cancel certain flows on pre-production firmware
Signalé sur October 31, 2025
In a pre-production firmware for Trezor Safe 7, a user could enter a dialog where pressing Cancel did not actually cancel the flow. This issue occurred only in non-critical paths such as staking delegation or similar actions, not in fund-sending flows.
The issue was present only in a pre-production firmware that was available for small group of people directly after the launch of Safe 7. The fix was already included in the version released to the general public.
Vulnérabilités résolues
Signalé par la communauté. Examiné. Résolu. Parce que votre sécurité n’est jamais optionnelle.
- Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injection25 mars 2026
- Open redirect on affiliate page20 mars 2026
- Biometric Verification bypassed in Trezor Suite with external monitor9 mars 2026
- Insufficient entropy on Trezor Model One with 12/18 words6 février 2026
- Bug in multisig verification10 janvier 2026
- Fix side-channel in BIP-39 mnemonic processing when unlocked24 septembre 2025