CVE-2026-18397 is an unauthenticated drive-by remote code execution vulnerability in Thales SConnect's browser extension and native host, with version 2.16.0.0 identified as vulnerable. The extension forwards messages from arbitrary websites and embedded iframes to the native host. Its custom RSA-2048 verifier allocates an uninitialized recovered-signature buffer and ignores a modular-exponentiation failure caused by an oversized signature, subsequently validating stale buffer contents. Heap spraying can make those contents satisfy signature checks. The same verifier protects website authorization and the InstallAddOns and CreateAddOnInstance operations, allowing an attacker to bypass origin authorization and add-on signature validation, then load and execute an unsigned DLL inside the Thales native host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical drive-by remote code execution vulnerability in Thales SConnect, hardware-token authentication middleware used to access SWIFT and government, banking, and insurance portals. The browser extension accepts messages from arbitrary webpages and embedded iframes. An oversized, invalid RSA signature causes signature verification to fail without populating a result buffer, but SConnect still reads the stale buffer. Researchers used heap spraying to forge an accepted verification result, allowing a malicious website to load a malicious DLL through the native host. Their demonstrated attack took six to 10 seconds, with approximately 18% success per attempt and no visible error on failed attempts. Identity-signing abuse, session theft, and fraudulent financial transfers are proposed consequences, not demonstrated outcomes. The reported CVSS 4.0 score is 9.4.
A drive-by remote code execution vulnerability affecting version 2.16.0.0 of the SConnect browser extension and native host. An uninitialized-memory flaw in its custom RSA-2048 token validation allows validation bypass and loading of DLL plugins. A malicious site or iframe could silently download and execute a DLL. The content reports a CVSS score of 9.4 and more than one million SConnect users.
A reported CVSS 9.4 drive-by remote code execution vulnerability in SConnect's browser extension and native host, affecting version 2.16.0.0. Its custom RSA signature verifier reads uninitialized heap memory after a failed modular-exponentiation operation and ignores the failure code. Heap spraying lets an attacker bypass website authorization and addon signature checks, causing an attacker-controlled DLL to execute inside the signed Thales native host. Any visited malicious site or embedded iframe can trigger the attack without user interaction. Researchers demonstrated exploitation in approximately 6–10 seconds; only the Chrome Web Store version was explicitly tested. The report describes patched Apple and Chrome extensions and removal of the Edge extension, but does not confirm automatic removal for existing Edge users.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.