Researchers have discovered a critical vulnerability in a hardware authentication program used to access highly sensitive global government and financial systems.
In cases where purely digital methods just aren’t secure enough, especially careful organizations may require that users authenticate to sensitive systems with multifactor authentication (MFA) hardware. After all, you wouldn’t want a simple password to allow hackers into a system that facilitates financial transfers or official government business. Hardware-based MFA requires some means of communicating between one’s hardware token and a website in question, though, which researchers continually find is the weak point in the whole arrangement.
“SConnect,” owned by the Thales Group conglomerate, is one such example of this. It’s a browser extension with more than 1 million users on the Chrome Web Store, and plenty more on other app stores. It’s used for authentication to major national government systems — like Qatar’s national identity provider, Tawtheeq, and the Swedish Tax Agency, Skatteverket — and various banking and insurance portals. Most notably, SConnect has long been one of the primary methods for accessing the Society for Worldwide Interbank Financial Telecommunication (SWIFT) banking system that supports the entire global financial apparatus.
In a report shared exclusively with Dark Reading ahead of publication, the browser extension aficionados at Bay Area Labs outlined a vulnerability in SConnect. The vulnerability allows attackers to perform drive-by remote code execution (RCE) attacks against users in a matter of seconds. And, the researchers say, the potential attack scenarios could get a lot worse.
Thales Group patched SConnect on the Apple App Store and Chrome Web Store in August and removed the app entirely from Microsoft Edge in September. It published a CVE, CVE-2026-18397, on Oct. 1. The company assigned it a “critical” 9.4 out of 10 in the Common Vulnerability Scoring System (CVSS) 4.0 scale, and users should update their instances as soon as possible.
Critical Vulnerability in Government, Banking Middleware
SConnect, like other sensitive authentication middleware, pairs a light browser extension with a workhorse desktop program. Users visit SConnect-integrated websites, mash their hardware keys into their computers or connected device readers, and the extension and native host facilitate the communication back and forth, like two little lawyers. If everything goes to plan, the software confirms that both the website and hardware token are trusted, authorized entities.
The first problem with SConnect was that the browser extension accepted messages from any webpage or embedded iframe, be it the SWIFT banking system or lowtpills[.]com. Thus, any attacker could attempt to step into an SConnect authentication flow if they could get a victim to the right webpage.
SConnect would still verify that the site was authorized, of course, by checking if it possessed a valid RSA digital signature from its vendor, Thales Group. In doing so, it reserved a buffer to hold the result of the RSA calculation. The app developers designed this check themselves, Bay Area Labs concluded, and they failed to protect against a scenario where the attacker supplied an invalid, oversized signature. In that case, the calculation would fail without writing anything to the reserved memory space. SConnect didn’t check whether the original calculation succeeded, but it did still read the stale buffer. If an attacker heap-sprayed it with carefully designed byte patterns meant to fake signature results, the software might accept the attacker’s ersatz replacement as valid. Using AI agents, Bay Area Labs succeeded at this about 18% of the times they tried, and meanwhile, failed attempts caused no visible error that could alert users they were under attack.
“At the end of the day,” explains Bay Area Labs founder James Arnott, “they implemented a cryptographic check, and they did it themselves. They didn’t use a library, and they messed it up.”
As a result, malicious websites could pass SConnect’s security check and load a malicious dynamic link library (DLL) through its native host for unfettered RCE. In their testing, the researchers were able to perform the attack end-to-end in six to 10 seconds flat. “Visit a page with a malicious iframe, then you have been infected. To be honest, from there, you can do pretty much whatever you want,” Arnott says.
It’s not an obvious vulnerability simply exploited, he admits, but the acceleration capabilities of AI put the exploit within reach: “It would have previously required nation-state effort. But when I was developing this exploit, it was very much agent-driven. The agents had Ghidra to decompile the native host, and then Frida to look at the memory to see what would be successful for the heap spray and what wouldn’t.”
Thales Group has not yet responded to Dark Reading’s request for comment on this story.
Defenders, Re-Evaluate Your SWIFT Banking Security
To authenticate to the SWIFT system, you’ll need a “3SKey” — a USB security token distributed to partner corporations for their most highly permissioned employees.
For years, the default software program connecting 3SKeys with the system they unlocked was SConnect. In September 2025, the SWIFT cooperative introduced a replacement called “Web Connect.” It has since been trying to move its corporate customers towards Web Connect, and away from SConnect.
SConnect is end of life (EoL) as of last month, but that doesn’t mean that everyone has made the jump yet.
“I suspect most people will still have it, if they’re using SWIFT, [since] SConnect is the fallback if Web Connect isn’t set up already,” Arnott posits. He admits that it’s very difficult to gauge the blast radius of this issue, though, as the banking industry keeps the particulars of its security practices close to the chest.
Bay Area Labs’ testing was limited by an inability to obtain a 3SKey, or tokens to other systems, like Qatar’s national government identity portal. Arnott suspects, however, that attack scenarios far beyond RCE against individual users could be possible with CVE-2026-18397. He speculates that “you could have a similar exploit chain like with Connective: to essentially relay challenges, to get the user’s identity card to sign documents. And then an attacker could steal the victim’s session and log in as them.”
Similarly, “once you have RCE in a banking system, it could be quite easy to look around, figure out whose computer you’re on, and try to transfer money,” he says. “I just can’t prove it because no one will send me a 3SKey, unsurprisingly.”


