Junglewise Threat Intelligence

CVE-2023-7345: Ledger Live integer parsing vulnerability in hw-app-eth

CVE-2023-7345 · Severity: medium · CVSS 6.5 · Published 2026-05-19

Executive brief

Ledger Live is a software application used to manage digital assets and authorize blockchain transactions on Ledger hardware wallets. A flaw in how the software processes specific transaction data allows attackers to trick users into signing transactions that differ from what is displayed on their screen. This could result in unauthorized asset transfers or the transfer of incorrect amounts, leading to financial loss.

Technical details

An integer parsing vulnerability exists in the Ledger hw-app-eth library (used by Ledger Live) due to incorrect handling of hexadecimal fields in EIP-712 typed data messages. Specifically, when a hexadecimal value contains an odd number of characters, the parser fails to process the field correctly, leading to truncation or misinterpretation of the data. An attacker can exploit this by presenting a malicious transaction request to a user; if signed, the resulting signature applies to the misinterpreted values rather than the intended ones. This allows for the authorization of unintended blockchain actions, such as asset transfers with manipulated amounts. The issue is fixed in ledgerhq/hw-app-eth version 6.34.7 and Ledger Live version 2.70.0.

Affected products

  • Ledger hw-app-eth < 6.34.7
  • Ledger Ledger Live < 2.70.0

Timeline

  • 2026-05-19: advisory: NVD and VulnCheck published advisory details.
  • 2026-05-19: disclosed

References