The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks. | |
| Title | SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability | |
| Weaknesses | CWE-130 CWE-252 CWE-347 CWE-457 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: THA-PSIRT
Published:
Updated: 2026-10-01T21:49:42.379Z
Reserved: 2026-07-30T14:55:56.425Z
Link: CVE-2026-18397
No data.
Status : Received
Published: 2026-10-01T22:17:01.220
Modified: 2026-10-01T22:17:01.220
Link: CVE-2026-18397
No data.
OpenCVE Enrichment
No data.