Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-05 · updated: 2026-10-05 · tags: [incident, financial-services] · confidence: high · severity: high · affected_sectors: [financial-services] · au_impact: true

Researchers at Bay Area Labs disclosed (report shared with Dark Reading ahead of publication) a critical vulnerability — CVE-2026-18397, published 1 October with a CVSS 4.0 score of 9.4 — in SConnect, the Thales-owned browser-extension-plus-native-host middleware used for hardware-token (3SKey) authentication to the SWIFT banking network, national government identity systems including Qatar's Tawtheeq and the Swedish Tax Agency (Skatteverket), and various banking and insurance portals, with more than 1 million Chrome Web Store users. The flaw pairs an unrestricted messaging interface — the extension accepted messages from any webpage or iframe — with a home-rolled RSA signature check whose result buffer could be heap-sprayed with forged signature data, letting an attacker-controlled site pass the site-authorisation check and load a malicious DLL through the native host for unauthenticated, drive-by remote code execution. Bay Area Labs demonstrated the end-to-end attack in six to ten seconds, and noted that AI agents driving Ghidra and Frida put within reach what would previously have required nation-state effort. Thales patched SConnect on the Chrome Web Store and Apple App Store in August and removed it from Microsoft Edge in September; affected versions are those below 2.16.1.0. Given SConnect's role as a primary authentication path into SWIFT, any financial institution or government user running an un-updated instance should verify its version immediately.

Attribute Detail
Sector Financial Services
Date 2026-10-05
Source Dark Reading
Reliability Tier 1
CVEs CVE-2026-18397