This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.
The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks. | |
| Title | SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability | |
| Weaknesses | CWE-130 CWE-252 CWE-347 CWE-457 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: THA-PSIRT
Published:
Updated: 2026-10-01T21:49:42.379Z
Reserved: 2026-07-30T14:55:56.425Z
Link: CVE-2026-18397
No data.
Status : Received
Published: 2026-10-01T22:17:01.220
Modified: 2026-10-01T22:17:01.220
Link: CVE-2026-18397
No data.
OpenCVE Enrichment
No data.