8 out of 10 Banks HATE This One Weird 3SKey RCE
SConnect, a popular browser extension and native host used for authentication with eIDs, 3SKeys, and hardware signing tokens, contains a remote code execution (RCE) vulnerability. The flaw arises from a flawed RSA-2048 token validation implementation that allows uninitialized memory to be exploited, enabling arbitrary DLLs to be loaded silently by any site or iframe the user visits. Version 2.16.0.0 of the extension and native host is affected. The vulnerability is tracked as CVE-2026-18397 with a CVSS score of 9.4, indicating critical severity.
AI Analysis
Technical Summary
The SConnect extension and its native host, used by over one million users for secure authentication with hardware tokens like 3SKeys, suffer from a critical remote code execution vulnerability (CVE-2026-18397). This vulnerability is due to a poor, custom implementation of RSA-2048 token validation that fails to properly initialize memory, allowing attackers to bypass validation and load arbitrary DLL plugins silently. This can be triggered by any website or iframe visited by the user, effectively enabling drive-by code execution. The affected version is 2.16.0.0 of both the extension and native host. The CVSS score of 9.4 reflects the high impact and exploitability of this vulnerability.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code on the victim's machine by silently downloading and loading malicious DLLs through the vulnerable extension and native host. This compromises the security of authentication tokens and potentially the entire system, posing a severe risk to users relying on SConnect for secure hardware token authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users and administrators should monitor official channels for updates or patches addressing CVE-2026-18397. Until a fix is available, consider disabling or uninstalling the vulnerable extension version 2.16.0.0 and its native host to prevent exploitation.
8 out of 10 Banks HATE This One Weird 3SKey RCE
Description
SConnect, a popular browser extension and native host used for authentication with eIDs, 3SKeys, and hardware signing tokens, contains a remote code execution (RCE) vulnerability. The flaw arises from a flawed RSA-2048 token validation implementation that allows uninitialized memory to be exploited, enabling arbitrary DLLs to be loaded silently by any site or iframe the user visits. Version 2.16.0.0 of the extension and native host is affected. The vulnerability is tracked as CVE-2026-18397 with a CVSS score of 9.4, indicating critical severity.
Reddit Discussion
TL;DR. SConnect - 1M+ users, an extension middleware+native host for authentication with eIDs, 3SKeys and other hardware signing tokens had a drive-by RCE which enabled any site or iframe a user saw to silently download and execute a dll due to a poor hand-rolled implementation of RSA-2048 token validation, enabling a use of uninitialized memory validation bypass which enabled "plugins" (DLLs) to be loaded. v2.16.0.0 of the extension and native host is vulnerable. CVE-2026-18397. CVSS 9.4.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The SConnect extension and its native host, used by over one million users for secure authentication with hardware tokens like 3SKeys, suffer from a critical remote code execution vulnerability (CVE-2026-18397). This vulnerability is due to a poor, custom implementation of RSA-2048 token validation that fails to properly initialize memory, allowing attackers to bypass validation and load arbitrary DLL plugins silently. This can be triggered by any website or iframe visited by the user, effectively enabling drive-by code execution. The affected version is 2.16.0.0 of both the extension and native host. The CVSS score of 9.4 reflects the high impact and exploitability of this vulnerability.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code on the victim's machine by silently downloading and loading malicious DLLs through the vulnerable extension and native host. This compromises the security of authentication tokens and potentially the entire system, posing a severe risk to users relying on SConnect for secure hardware token authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users and administrators should monitor official channels for updates or patches addressing CVE-2026-18397. Until a fix is available, consider disabling or uninstalling the vulnerable extension version 2.16.0.0 and its native host to prevent exploitation.
Technical Details
- Source Type
- Subreddit
- netsec
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":30,"reasons":["external_link","newsworthy_keywords:rce","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["rce"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6abfdc43a43b0b3b89d7b851
Added to database: 10/02/2026, 16:30:59 UTC
Last enriched: 10/02/2026, 16:31:03 UTC
Last updated: 10/02/2026, 17:15:56 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.