A critical zero-day vulnerability tracked as CVE-2026-18397 (CVSS 9.8, GHSA-cq27-3937-pqqv) has been uncovered in SConnect, a ubiquitous browser PKI extension and native messaging host developed by Gemalto/Thales and deployed across thousands of international commercial banks, corporate treasury portals, and government digital signature infrastructures. The flaw permits any arbitrary website visited by a user to dispatch malicious JSON-RPC commands to the installed SConnect native messaging host, triggering heap memory corruption and executing arbitrary code on the client machine outside of the browser sandbox.
The SConnect Native Messaging Architecture
Because modern web browsers (Chrome, Firefox, Edge) operate inside strict sandboxes that forbid direct communication with physical USB smart cards and cryptographic hardware security modules (HSMs), web applications rely on browser extensions paired with a Native Messaging Host executable installed on the operating system.
When an enterprise user authenticates to a banking portal or electronically signs an ACH treasury transfer, JavaScript on the webpage communicates with the SConnect browser extension, which forwards raw binary signing requests to the local SConnect native host binary (sconnect-host.exe or Linux/macOS equivalent) via standard I/O (stdin/stdout).
Exploit Chain: Origin Bypasses and Heap Corruption
The security defect combines an architectural access control breakdown with low-level memory mismanagement:
1. Missing Web Origin Validation
The SConnect extension was configured with broad wildcard permissions ("externally_connectable": { "matches": ["*://*/*"] }), allowing any public website to open a messaging port to the extension. The native host component failed to validate whether the calling domain was an authorized banking portal, accepting requests from any origin.
2. Cryptographic Parsing Memory Corruption (CWE-119)
When receiving digital signature parameter blocks, the native host binary deserializes complex ASN.1 structures representing X.509 certificate chains and cryptographic hashes. By supplying an oversized, malformed ASN.1 integer length field in the JSON-RPC signing payload, an attacker induces an integer overflow in the buffer allocation routine:
// Malicious JavaScript executed on drive-by attacker website:
const sconnectExtensionId = "com.gemalto.sconnect";
chrome.runtime.sendMessage(sconnectExtensionId, {
method: "PKI_SignPayload",
params: {
slotId: 0,
mechanism: "SHA256_RSA_PKCS",
// Crafted oversized buffer triggering heap integer wrap
dataBuffer: "".repeat(65536) + "AAAA",
asn1LengthOverride: 0xFFFFFFFF
}
}, (response) => {
console.log("Payload dispatched to native host:", response);
});
The integer wrap causes the native host to allocate a small heap chunk while copying 64 kilobytes of shellcode into the buffer. This triggers a heap-based buffer overflow, overwriting adjacent function pointers and executing arbitrary shellcode with the privileges of the logged-in desktop user.
| Component Tier | Intended Security Boundary | Vulnerability Breakdown |
|---|---|---|
| Web Browser Layer | Sandbox confines JavaScript to origin | Wildcard extension permissions allow cross-origin dispatch |
| Native Messaging Layer | Validate calling extension and domain | Missing origin check allows untrusted sites to send commands |
| Native Host C++ Binary | Safe ASN.1 parsing and PKI signing | Integer overflow triggers heap memory corruption and RCE |
Defensive Remediation Guidelines for Financial Institutions & Users
- Deploy Updated SConnect Client: Organizations must roll out the latest SConnect desktop installer (version 2.14.0 or higher) across all corporate endpoints. The update restricts origin permissions strictly to verified enterprise domains and patches ASN.1 parsing memory checks.
- Enforce Browser Extension Allowlisting: Enterprise IT administrators should deploy Google Chrome and Microsoft Edge Group Policy Objects (GPOs) to restrict extension installations, permitting the SConnect extension to load only on corporate-managed devices.
- Disable or Remove Idle Extensions: End users who no longer require smart card banking signatures should navigate to
chrome://extensionsand uninstall the SConnect extension to permanently eliminate the attack surface.



