Researchers disclosed CVE-2026-18397, a drive-by remote code execution vulnerability in SConnect, a browser extension and native host reportedly used by more than one million users for hardware-token authentication and digital signing. The flaw, reported with a CVSS score of 9.4, was demonstrated against version 2.16.0.0 and allowed any visited website or embedded iframe to silently download and execute an unsigned DLL. An uninitialized-memory flaw in SConnect’s custom RSA-2048 verifier, combined with heap spraying, bypassed website authorization and add-on signature checks. SConnect supports sensitive workflows involving SWIFT, 3SKey, electronic IDs, and other signing tokens.
Thales received the report on June 29, 2026, subsequently released updates through Apple and Chrome distribution channels, and removed the Edge extension in September. Researchers could not confirm whether existing Edge installations were automatically removed. Organizations should inventory SConnect deployments, verify that both browser extensions and native hosts are updated, and explicitly check for remaining Edge installations, prioritizing financial authentication and signing workstations. The disclosure did not establish the full deployment footprint, demonstrate unauthorized interactions with connected security tokens, or report exploitation in the wild.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Thales published CVE-2026-18397 for the SConnect remote code execution vulnerability on October 1, 2026, assigning it a critical CVSS 4.0 score of 9.4.
The SConnect Edge extension was removed from distribution on September 13, when it had approximately 89,000 users. Researchers could not confirm whether existing installations were automatically uninstalled.
Thales released a SConnect patch through the Chrome Web Store on August 12. Researchers tested the updated Chrome extension, which referenced a new native host and could no longer communicate with the old host.
Thales released a SConnect patch through the Apple App Store on August 7.
Thales confirmed the reported vulnerability and reserved a CVE on July 3. The issue was identified as CVE-2026-18397, with a reported CVSS score of 9.4.
Researchers reported the SConnect vulnerability to Thales PSIRT on June 29, 2026. The flaw enabled a website or embedded iframe to silently download and execute an unsigned DLL.
Researchers disclosed how an uninitialized-memory flaw in SConnect's custom RSA-2048 verifier, combined with heap spraying, bypassed website authorization and add-on signature checks in extension and native host version 2.16.0.0. Their proof of concept executed an unsigned DLL through a website or iframe in approximately six to ten seconds without requiring user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcereddit.com
Open sourceamibeingpwned.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.