Skip to finding
important · Zero-click

Any web page or embedded iframe can silently execute native code through a vulnerable Thales SConnect installation.

Affects

Thales SConnect, browser-extension middleware and a Windows native host used with eIDs, SWIFT 3SKey and other hardware signing tokens.

The path applies to Windows browsers with the vulnerable SConnect extension and native host installed.

Detail and 4 sources

Heap spraying after a failed RSA operation lets attacker content forge origin and package signatures, causing SConnect to load and invoke an attacker DLL.

The current Chrome Web Store listing shows the remediated 2.16.1.2 release.

The installed-helper requirement narrows the population, and a remediated release is available.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026