RESEARCHERS have disclosed a critical vulnerability in SConnect, a hardware-authentication middleware component used to access highly sensitive global government and financial systems, including the SWIFT network. The flaw resides in the browser extension portion of SConnect, which could accept messages from any webpage or embedded iframe.
Attackers could lure victims to a malicious page and, by abusing a flawed cryptographic check, cause SConnect to load a malicious dynamic-link library (DLL) in the native host, enabling remote code execution (RCE). Bay Area Labs reports that the attack can be carried out end-to-end in as little as six to ten seconds in controlled conditions, with AI-assisted tooling increasing the feasibility of the exploit.
Thales Group issued patches in August for the Apple App Store and Chrome Web Store, removed the extension from Microsoft Edge in September, and publicly documented the vulnerability as CVE-2026-18397 on 1 October. The vulnerability has been described as critical, with a CVSS 4.0 score of 9.4/10. While SConnect is end-of-life as of September 2025, many organisations still rely on it as a fallback when Web Connect is not configured.
Analysts emphasise that the real-world impact could extend beyond RCE to footholds in banking or government sessions, potentially enabling identity-related abuse or fraudulent transactions if attackers gain access to a 3SKey-enabled environment. Organisations using SWIFT should prioritise upgrading to Web Connect where possible and reassessing residual SConnect deployments.