This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.
The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks. | |
| Title | SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability | |
| Weaknesses | CWE-130 CWE-252 CWE-347 CWE-457 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: THA-PSIRT
Published:
Updated: 2026-10-01T21:49:42.379Z
Reserved: 2026-07-30T14:55:56.425Z
Link: CVE-2026-18397
No data.
Status : Received
Published: 2026-10-01T22:17:01.220
Modified: 2026-10-01T22:17:01.220
Link: CVE-2026-18397
No data.
OpenCVE Enrichment
Updated: 2026-10-01T23:30:14Z