Skip to finding
important · RCE / zero-click

Any web page can make a vulnerable SConnect installation load an unsigned DLL.

Affects

Thales SConnect, browser-to-native middleware used by electronic-identity, signing and financial-authentication products on Windows workstations.

A failed RSA operation leaves attacker-influenced data in an uninitialized verification buffer, bypassing the origin token and both package-signature layers.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, October 4, 2026