A Broken Cryptographic Check in SWIFT's Login Tool Handed Attackers Full PC Control
A homemade RSA verification routine in Thales Group's SConnect software left SWIFT banking access, Qatar's national identity system, and the Swedish Tax Agency open to silent drive-by attacks. The patch is out. Most users haven't moved.

Key points
- CVE-2026-18397, published 1 October 2026, carries a CVSS 4.0 score of 9.4 and lets an attacker run arbitrary code on a victim's computer without any credentials.
- SConnect, made by Thales Group, has more than one million installs on the Chrome Web Store and is a primary access tool for the SWIFT international banking network.
- Researchers at Bay Area Labs found that a home-built RSA verification routine inside SConnect could be bypassed roughly 18 percent of the time using an AI-assisted technique, with failed attempts producing no visible warning.
- Thales patched SConnect on Chrome and Apple App Store in August 2026 and pulled the app from Microsoft Edge entirely in September; the CVE was filed 1 October 2026.
- SConnect reached end-of-life last month, but Bay Area Labs founder James Arnott believes most SWIFT-connected organisations still have it installed as a fallback.
SConnect is a middleman. Users at banks and government agencies plug a USB security token into their computer. A browser extension and a companion desktop program called a native host pass messages back and forth to confirm that both the website and the token are legitimate before granting access. The system is built for environments where a password alone isn't enough: executing international wire transfers through SWIFT, a cooperative that underpins money movement between banks worldwide, being the clearest example.
The flaw, CVE-2026-18397, lives in that native host component. Bay Area Labs found two problems stacked on top of each other.
How did attackers actually break it?
SConnect accepted messages from any website, not just trusted ones. Separately, the code meant to verify a site's identity contained a critical mistake.
When SConnect checked whether a website held a valid RSA digital signature (a cryptographic stamp of approval issued by Thales), it reserved a small block of memory for the result. If an attacker supplied an oversized, invalid signature, the check failed without writing anything to that memory. SConnect never confirmed whether the check had actually succeeded. It simply read whatever happened to be sitting there already.
Bay Area Labs used heap spraying, flooding that memory area with byte patterns crafted to resemble a valid result, to trick the software into accepting a fraudulent site as approved. Using AI agents to automate and refine the attack, researchers succeeded roughly 18 percent of the time. Every failed attempt produced no error or warning for the user.
"They implemented a cryptographic check, and they did it themselves. They didn't use a library, and they messed it up," Bay Area Labs founder James Arnott told Dark Reading.
Our August story on a near-identical flaw in a Belgian government browser extension showed the same pattern: authentication middleware, custom cryptography, catastrophic outcome. This is the second time in two months we've reported a government-grade browser extension handing attackers remote code execution through a broken verification step.
Once the fake check passed, the attacker's site could load a malicious DLL (a dynamic link library, an external code file Windows programs call at runtime) through the native host, giving full control of the victim's machine. In testing, the attack took between six and ten seconds end to end. Visiting a page containing a hidden malicious iframe was enough.
Should SWIFT users be worried right now?
Yes, particularly those who haven't completed the migration to SWIFT's replacement tool.
In September 2025, SWIFT introduced a successor called Web Connect and began pushing corporate customers to migrate. SConnect officially reached end-of-life last month. Arnott told Dark Reading he suspects most organisations running SWIFT access still have SConnect installed, because Web Connect requires a separate setup process before it can serve as the primary authenticator.
| Event | Date |
|---|---|
| SWIFT Web Connect introduced | September 2025 |
| Thales patches Chrome and Apple App Store | August 2026 |
| Thales removes SConnect from Microsoft Edge | September 2026 |
| CVE-2026-18397 published | 1 October 2026 |
| SConnect end-of-life | October 2026 |
Arnott could not obtain a SWIFT 3SKey USB token, or tokens for Qatar's Tawtheeq identity portal and Sweden's Skatteverket tax system, to test further. He told Dark Reading that once an attacker has code execution on a banking employee's machine, locating account details and attempting a fraudulent transfer becomes a practical next step, though he can't prove it without hardware no one will send him.
Thales Group did not respond to requests for comment before publication.
The target profile is what makes this serious. SConnect doesn't sit on consumer laptops. It sits on the machines of people authorised to move large sums of money or verify national identities. A one-in-six success rate on a silent, six-second attack is a meaningful number in that environment, and the organisations still running end-of-life software because migration is inconvenient are exactly the ones most exposed.
What should affected users do?
If you use SConnect for any purpose, check your version immediately. Thales has released patched builds on the Chrome Web Store and Apple App Store. If your organisation accesses SWIFT systems, IT should be prioritising migration to Web Connect and confirming SConnect has been removed or updated on every relevant machine. Users on Microsoft Edge should note the app has been pulled from that store entirely. Don't wait for a scheduled update cycle.



