CVE Tools

SWIFT Banking & Government Middleware Enables RCE

Dark ReadingBy Nate Nelson

PoC publicSConnectBay Area Labs

Our summary

Security researchers at Bay Area Labs have found a critical flaw, tracked as CVE-2026-18397, in Thales Group's SConnect browser extension, which handles hardware-token authentication for SWIFT banking transfers, Qatar's Tawtheeq national ID system, Sweden's Skatteverket tax agency, and various bank and insurance portals. The bug stems from a homegrown RSA signature check: when an attacker submits an oversized, invalid signature, the verification silently fails but SConnect still reads the leftover buffer contents, letting a heap-sprayed fake result pass as legitimate roughly 18% of the time. A malicious webpage or embedded iframe can exploit this to load a rogue DLL through SConnect's native host, achieving full remote code execution in as little as six to ten seconds without any visible error. Thales patched the Chrome and Apple App Store versions in August, pulled the extension from Microsoft Edge in September, and rated the flaw 9.4 on CVSS 4.0; since SConnect reached end-of-life last month in favor of SWIFT's newer Web Connect tool, organizations still relying on it as a fallback should update or migrate immediately, as researchers warn the bug could potentially be chained to hijack user sessions and banking transactions.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure