Retour au portail de sécurité
Solana signing display improvement
Signalé sur June 12, 2026
Certain Solana account-creation instructions did not surface all signed fields on the device's confirmation screen, weakening the What-You-See-Is-What-You-Sign guarantee for those flows. The affected screens now display the complete set of relevant fields prior to confirmation.
Vulnérabilités résolues
Signalé par la communauté. Examiné. Résolu. Parce que votre sécurité n’est jamais optionnelle.
- Unauthenticated Remote DoS via xpub Change-Index Amplification19 mai 2026
- Unauthenticated Remote Memory Exhaustion via Unbounded Timestamp Array19 mai 2026
- Ethereum's SLIP-24 payment-request branch in production firmware signs attacker calldata under cover of verified-swap UI16 mai 2026
- Cross-Origin Popup Takeover in Trezor Connect popup3 mai 2026
- Lock bypass in SD-protect-only configuration allows signing after LockDevice/autolock14 avril 2026
- Solana ALT recipient confirmation mismatch6 avril 2026