On August 28, Ledger released an official announcement disclosing a command interleaving vulnerability in its Secure SDK. This vulnerability, classified as a 'time-of-check to time-of-use' security flaw, was introduced in August 2025 and affects all applications built on versions v26.6.0 and below, though device firmware remains unaffected. There is currently no evidence to suggest that this vulnerability has been exploited in practice.
