Back to security portal
Biometric Verification bypassed in Trezor Suite with external monitor
Reported on March 9, 2026
Biometric authentication in Trezor Suite could be bypassed when the functionality was not available on the host device. This could happen, for example, when a laptop was connected to an external monitor and its lid was closed. This beat the purpose of biometric authentication which should prevent other users of the host device from unauthorized access to the app.
Resolved vulnerabilities
Reported by the community. Investigated. Resolved. Because your security is never optional.
- Inability to cancel certain flows on pre-production firmwareOctober 31, 2025
- Fix side-channel in BIP-39 mnemonic processing when unlockedSeptember 24, 2025
- Donjon's Trezor Safe 3 evaluationNovember 12, 2024
- Missing confirmation in the ECDHSessionKey callNovember 26, 2023
- XSS in Trezor Connect legacy versionsFebruary 7, 2023
- Insufficient field size check in ProtobufJuly 12, 2021