CVE-2026-65058
Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker could present calldata to a victim then supply a different tail that changes the signed transaction. Fixed in 70c9b0c.
Published:Jul 21, 2026
Last Modified:Jul 30, 2026
EPS:Jul 21, 2026
EPSS Score:0.00279
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Trezor
Product
Safe 3
Trezor
Safe 3
Vendor
Trezor
Product
Safe 5
Trezor
Safe 5
Vendor
Trezor
Product
Safe 7
Trezor
Safe 7
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
