DEV Community

Anoymask
Anoymask

Posted on

SConnect CVE-2026-18397: Heap Spraying Bypasses Signature Verification for Drive-by RCE

1. Basic Information

  • Original Title: 8 out of 10 Banks HATE This One Weird 3SKey RCE
  • Source: Bay Area Labs
  • Published Date: 2026-10-02
  • Updated Date: None
  • Severity: Critical
  • Severity Basis: CVSS 4.0 is 9.4. When a victim visits a malicious web page or iframe, an unsigned DLL can execute within the native host without additional user interaction or warnings. SConnect is used for high-security authentication such as 3SKey, and the Chrome extension had over one million users. Active exploitation in the wild remains unconfirmed.
  • Original Link: Bay Area Labs
  • Related Sources: Dark Reading, SWIFT 3SKey, 3SKey migration notice, Thales CNA: CVE-2026-18397, Swift: SConnect critical update
  • Associated Malware: None
  • Associated Threat Groups: None
  • Associated CVE: CVE-2026-18397
  • Related Products: SConnect 2.16.0.0, Thales SConnect, SWIFT 3SKey

2. Quick Summary

In the Chrome version of SConnect 2.16.0.0, researchers demonstrated remote code execution (RCE) by sending messages from an arbitrary web page or iframe to the native host, using heap spraying to influence the contents of an uninitialized buffer, bypassing signature verification, and loading a malicious addon DLL into a legitimate Thales process. The 6 to 10 second duration reflects the time required in the researcher's PoC. Thales advisory information identifies versions prior to 2.16.1.0 as affected.

3. Attack Flow

Flow 1: From Arbitrary iframe to Malicious Addon DLL Execution

  1. The victim visits a malicious web page or a page containing a malicious iframe. The SConnect content script runs across all frames (all_frames) and accepts messages from any origin.
  2. The attacker supplies an oversized signature that causes RSA modular exponentiation to fail, then repeatedly sprays the native host process's heap through a long-lived native messaging connection. Failed attempts produce no visible warning to the user.
  3. When the uninitialized buffer resembles a valid PKCS#1 block, SConnect incorrectly determines that the origin token signature is valid.
  4. Following the origin token validation bypass, the attacker exploits the same flaw to bypass signature verification for the addon package's manifest and signature.json respectively. A total of three stages of signature verification must be bypassed before DLL execution.
  5. The native host loads the unsigned addon.dll via LoadLibrary and invokes onCreate to execute attack code within a legitimate Thales process.

4. Attacker Position and Execution Location

  • A remote attacker who can control an arbitrary web page or embedded iframe viewed by the victim.
  • Code executes within the SConnect native host process on the endpoint.

5. Victim and Administrator Perspective

Victims

  • The PoC completes within 6 to 10 seconds without any on-screen warnings, and failures result in silent errors, meaning the victim may remain unaware.

Administrators

  • Inference: Available telemetry for investigation may include browser-to-extension messages, native host network requests, addon package deployment, and unknown DLL loads into the SConnect process. These do not necessarily appear completely in standard logs. Specific malicious file hashes have not been published.

6. Success and Failure Conditions

Success Conditions

  • Vulnerable versions of the SConnect extension and native host are present on the endpoint, and a page or iframe can send messages to the content script. Researcher demonstration was performed using the Chrome version 2.16.0.0.
  • Heap spraying successfully shapes uninitialized buffers into the targeted pattern to pass signature verification.
  • Acquisition of a malicious addon package allows the native host to load the DLL.

Failure Conditions

  • Official 3SKey guidance instructs updating to SConnect Host 2.16.1.0 and extension 2.16.1.1, verifying the application of both. Other deployments must check vendor patching procedures and verify that legacy native hosts are removed.
  • Discontinuing SConnect and migrating to alternative methods such as Web Connect.
  • Disable and remove unnecessary SConnect extensions and native messaging hosts. If SConnect remains in use, apply the updates and control DLL execution. Allowlisting the extension or the signed native host alone is insufficient to prevent malicious addon DLLs from executing.

7. Impact of Successful Exploitation

  • Drive-by remote code execution on the victim endpoint.
  • Execution of an unsigned DLL within a legitimate, signed Thales process.
  • Unverified possibility: Issuing APDU commands to connected 3SKey/eID devices.

8. Observable Logs

Email

  • Delivery methods have not been identified. If URL delivery emails are used, monitor for clicks and browser events.

Proxy / SWG / DNS

  • Monitor for HTTP(S) requests where the SConnect native host retrieves origin tokens and addon packages, or payload downloads originating from unknown domains.

Endpoint / EDR

  • Check for unknown DLL loads into SConnect or native host processes, extraction of addon archives, LoadLibrary calls, child process creation, and file creation.

Identity / IdP

  • Review authentication and signing events for portals utilizing 3SKey/eID, though researchers did not verify token manipulation.

SaaS / Cloud

  • Check SWIFT and banking portals for abnormal 3SKey logins, signatures, or transactions.

Network

  • Correlate browser activity and extension-to-native-host messaging with outbound HTTP(S) requests from the native host to the attacker's origin or payload host. Native messaging is local interprocess communication, not a network connection. If TLS obscures the payload, use EDR or other endpoint telemetry to identify the process responsible for the outbound request.

9. Attack Success Determination

Confirm Initial Execution

  • Public Information and Criteria: Public Information: Researchers demonstrated an RCE PoC in 6 to 10 seconds using the Chrome version of SConnect 2.16.0.0, reporting a heap spraying success rate of approximately 18% without using Frida. The 18% figure does not represent the success rate of the entire attack chain, and total trial counts were not disclosed. Active exploitation in the wild has not been reported. Criteria: Confirm evidence that the SConnect native host loaded an attacker-supplied addon DLL and executed its code.
  • Scope: Client endpoints with SConnect installed
  • Associated CVE: CVE-2026-18397

Confirm Subsequent Compromise

  • Public Information and Criteria: Public Information: Issuing APDU commands to 3SKey/eID devices was suggested as a possibility but was not verified by researchers. Criteria: Classified at this stage if portal-side evidence confirms unauthorized authentication, signing, or transactions following RCE.
  • Scope: Authentication and signing using hardware tokens
  • Associated CVE: CVE-2026-18397

10. Investigation Playbook

Trigger

  • Triggered by SConnect Host versions prior to 2.16.1.0, extensions that have not received the security update, residual legacy native hosts, unknown DLL loads into SConnect processes, or anomalous 3SKey utilization.

Initial Verification

  • Check extension and native host versions, browsers, installation channels, remaining SConnect extensions installed from the withdrawn Edge store listing, portals in use, and visited URLs.

Endpoint

  • Preserve SConnect process memory and modules, addon directories, download history, browser history, and EDR process and network events.

Authentication and Cloud

  • Review logins, signatures, transactions, and events associated with token serial numbers in 3SKey/eID portals.

Subsequent Operations

  • Track post-RCE process creation, credential access, persistence configurations, and network connections.

Containment

  • Isolate endpoints from the network, update or remove SConnect after evidence preservation, and eliminate legacy native hosts. Revoke and reissue hardware tokens if necessary.

Decision Categories

  • Categorize and record malicious page visits, signature verification bypass attempts, DLL loads, code execution, and impact on tokens or transactions.

11. Defense and Detection Ideas

Single Event

  • Generate alerts for unknown or unsigned DLL loads into legitimate SConnect native hosts.

Chronological Correlation

  • Correlate browser navigation, native messaging, rapid iterative requests, addon downloads, and DLL loads as a unified attack sequence.

Hunting Perspectives

  • Search for SConnect Host versions prior to 2.16.1.0, residual legacy Edge store versions or native hosts, unknown addon DLLs, and SConnect-originating network access.

Log Limitations

  • No errors are displayed to the user, and malicious file hashes remain unpublished. Detection is difficult without extension inventories and module load telemetry.

Priority Countermeasures

  • Prioritize applying official patches or migrating to alternative methods, removing legacy native hosts, enforcing browser extension governance, and monitoring DLL loads.

12. Facts, Inference, and Hypothesis

Facts

  • SConnect browser extensions accept messages from arbitrary web pages or iframes and forward them along with origin information to the native host.
  • The custom RSA-2048 verification routine in SConnect 2.16.0.0 validates uninitialized 256-byte buffers allocated via malloc without checking return codes when modular exponentiation fails and fails to write to the buffer.
  • Researchers supplied 257 bytes of 0xFF as a signature and used a long-lived native messaging connection to spray the native host process's heap, making the uninitialized buffer resemble a valid PKCS#1 block. They reported an approximate 18% success rate in heap spraying without Frida, though total trial counts were not provided, and this does not represent the RCE success rate of the entire attack chain.
  • After bypassing origin token validation, signature verification was bypassed across two additional stages (manifest and signature.json), allowing unsigned addon.dll to be loaded via LoadLibrary into the legitimate, signed Thales native host process and executing the onCreate export function. The PoC achieved RCE in 6 to 10 seconds without displaying errors to the user.
  • Researchers indicated the theoretical possibility of issuing APDU commands to 3SKey/eID devices but did not possess physical tokens to verify it. Active exploitation in the wild has not been reported.
  • According to researchers, Apple and Chrome versions were patched on 2026-08-07, and the Edge store version was removed on 2026-09-13. Demonstration was performed on the Chrome version; whether the same vulnerability applies to other distribution channels is an estimation by researchers. Automatic removal of existing Edge store versions has not been confirmed.
  • Thales advisory information identifies SConnect versions prior to 2.16.1.0 as affected. Swift advises updating to SConnect Host 2.16.1.0 and extension 2.16.1.1 for 3SKey, with Chrome/Edge updates via the Chrome store and Firefox updates manually. This is distinct from verifying the removal of legacy removed Edge store versions.

Inference

  • Because the malicious DLL executes inside the signed native host process, allowlisting that trusts the host executable without checking the DLLs it loads may fail to block the malicious addon.
  • Even after removing or updating SConnect, separate investigations are required to determine if DLLs were previously executed, credentials were harvested, or tokens were manipulated.

Hypothesis

No additional hypotheses. Unverified items are listed in "14. Unresolved Items and Further Investigation."

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1189 Drive-by Compromise high PoC demonstrated RCE in Chrome without additional user interaction after viewing a web page or iframe. Page viewing is required, and CVSS user interaction (UI) is Passive.
T1203 Exploitation for Client Execution high Executes code on client endpoints by exploiting uninitialized memory and signature verification flaws.

14. Unresolved Items and Further Investigation

  • Update deployment status across all distribution channels and the presence of residual legacy Edge store versions. The patch level for 3SKey is Host 2.16.1.0 / extension 2.16.1.1.
  • The full scope of banks and government services utilizing SConnect.
  • Active exploitation in the wild, malicious addon hashes, and known attack infrastructure.

15. Impact on SOCs and Organizations

SConnect may remain installed on endpoints used by finance departments or overseas offices of Japanese organizations to access foreign banking services, government portals, eID services, or 3SKey. Check browser extension inventories, native hosts, and legacy installation directories, paying particular attention to SConnect extensions installed from the withdrawn Edge store listing.

16. Summary by Role

  • SOC: Review available telemetry for DLL downloads and loads by the SConnect native host, messages originating from arbitrary web origins and relayed through the extension, and unknown modules loaded within the legitimate Thales host process.
  • Administrators: For 3SKey, verify the application of SConnect Host 2.16.1.0 and extension 2.16.1.1, and proceed with migration to Web Connect as advised by SWIFT. Do not assume legacy Edge store versions were eradicated from endpoints simply because they were removed from the store; verify via inventory.
  • Users: Until SConnect updates are complete, avoid opening untrusted web pages or embedded content on endpoints used for 3SKey and similar services.

Top comments (0)