SConnect Flaw Lets Malicious Websites Reach a Native Host

Thales SConnect flaw CVE-2026-18397 lets malicious sites bypass signature checks and execute code via native host. Update now, SWIFT urges Web Connect.

SConnect Flaw Lets Malicious Websites Reach a Native Host
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 6 min

A browser extension exposes a path to code execution

Thales Group’s SConnect authentication software contains a critical vulnerability that could allow a malicious website to run code on a visitor’s computer. Thales published CVE-2026-18397 on Oct. 1 and assigned it a score of 9.4 out of 10, Critical, under CVSS 4.0.

SConnect pairs a browser extension with a desktop application, known as its native host, to support hardware-token authentication. Deployments include SWIFT’s banking system, Qatar’s national identity provider Tawtheeq, Sweden’s Tax Agency, Skatteverket, and banking and insurance portals. The Chrome Web Store lists more than 1 million users, with additional users obtaining the software through other app stores.

In its report on Bay Area Labs’ research, Dark Reading describes how a webpage or embedded iframe could send messages to the extension without being restricted to trusted sites. That could let an attacker target an SConnect authentication flow when a victim visits a prepared page.

The National Vulnerability Database characterizes the issue as unauthenticated remote code execution caused by cryptographic weaknesses and memory-management problems in the native-host component. Its CWE classifications are CWE-130, CWE-252, CWE-347, and CWE-457.

An unsuccessful RSA calculation could leave stale data

SConnect checks whether a site is authorized by validating an RSA digital signature issued by Thales. Bay Area Labs said the developers implemented this cryptographic check themselves instead of relying on a library.

The researchers’ analysis found a problematic path for an invalid, oversized signature. The RSA calculation could fail without writing a result into the buffer reserved for it. SConnect did not confirm that the calculation had succeeded before reading that buffer.

As a result, old data in memory could be treated as the calculation’s output. Bay Area Labs said carefully arranged heap-spray data could make those stale contents resemble a valid signature, potentially fooling the site-authorization check.

The flaw therefore combines the extension’s permissive messaging interface with weaknesses in signature validation and memory handling. The NVD description also identifies the interaction between cryptographic and memory-management issues in the native host.

Researchers report end-to-end RCE in seconds

After bypassing the site check, a malicious page could reportedly use SConnect’s native host to load a malicious dynamic-link library (DLL), giving the attacker remote code execution on the victim’s computer. Bay Area Labs said its end-to-end test took six to 10 seconds.

The researchers used Ghidra to decompile the native host and Frida to inspect memory and tune their heap spray. They also used AI agents during exploit development, reporting successful signature forgery in about 18% of attempts. Failed attempts produced no visible error that would alert the user.

That 18% figure describes the researchers’ signature-forgery attempts; it is not a measure of the likelihood that a particular user or organization will be compromised. The demonstrated impact was code execution on an individual user’s machine.

Bay Area Labs also discussed possible consequences beyond that access, but did not demonstrate them. Its founder, James Arnott, suggested that an attacker on a banking workstation might inspect the machine or try to make unauthorized transfers. The researchers also raised a possible scenario involving relayed authentication challenges, an identity card signing documents, and subsequent session theft and impersonation. Those scenarios remain possibilities, not verified capabilities of the reported exploit.

SWIFT transition and testing limits leave exposure uncertain

One notable SConnect deployment involves SWIFT’s 3SKey, a USB security token issued to partner corporations for highly privileged employees. SWIFT introduced Web Connect in September 2025 and has encouraged corporate customers to transition from SConnect. SConnect may still be used as a fallback when Web Connect has not been configured.

Bay Area Labs said it could not obtain a SWIFT 3SKey or tokens for other systems, including Qatar’s government identity portal. Its testing therefore did not establish how the exploit would work across those particular deployments. The report also says the scale of exposure among banking organizations is difficult to determine because details of their security practices are not public.

The report says SConnect reached end of life in the month before publication, without giving an absolute date for that milestone. Thales made updates available through the Apple App Store and Chrome Web Store in August, then removed the application from Microsoft Edge in September. The supplied reporting does not specify a year for those store changes.

A linked SConnect notice identifies a critical update for host version 2.16.1.0 and extension version 2.16.1.1. The report does not explicitly confirm that these versions fix CVE-2026-18397, so they should not be treated as a verified fixed-version mapping.

Apply available updates and consider Web Connect

Organizations and users that still rely on SConnect should install available updates as soon as possible. The reporting does not identify a definitive version that remediates the CVE.

SWIFT customers should move to Web Connect where applicable, while checking whether SConnect remains installed as a fallback. The reported removal from Microsoft Edge does not establish that the software has been removed from systems where it was previously installed.

Bay Area Labs conducted the vulnerability analysis and exploit testing. At the time of Dark Reading’s report, Thales had not responded to the publication’s request for comment.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →