A vulnerability, which was classified as problematic, was found in Trezor Safe 3, Trezor Safe 5 and Trezor Safe 7. Affected by this issue is the function sign_tx/sign_tx_eip1559 of the component Ethereum Signing Confirmation. Such manipulation leads to business logic errors.

This vulnerability is traded as CVE-2026-65058. An attack has to be approached locally. There is no exploit available.