Is this an attack that can be mitigated by a firmware update?
"In the case of timing attacks against targets whose computation times are quantized into discrete clock cycle counts, an effective countermeasure against is to design the software to be isochronous, that is to run in an exactly constant amount of time, independently of secret values. This makes timing attacks impossible.[14] Such countermeasures can be difficult to implement in practice, since even individual instructions can have variable timing on some CPUs."
It's not an attack. It's just something that the Ledger security team has been working on.