<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Critical Flaw Let Any Website Run Code on Machines Used for SWIFT

Critical SConnect vulnerability in SWIFT login software allows remote code execution; users urged to switch to Web Connect immediately.
Content Team

Researchers at Bay Area Labs have uncovered a critical vulnerability (CVE-2026-18397, scored 9.4 by Thales on the CVSS 4.0 scale) in SConnect, a browser-based authentication tool with more than a million Chrome installs, used to access SWIFT banking networks and major government systems in Qatar and Sweden. The flaw lets attackers execute remote code on victims' machines via a malicious webpage, or any iframe loaded onto one — no interaction required beyond a visit, and 6–10 seconds in the researchers' testing.

The bug stems from a homegrown cryptographic check. SConnect verifies a site's RSA signature inside a block of memory it never clears first, so whatever was there before stays put. Feed it an oversized signature and the calculation fails without writing anything — but the check reads that block anyway. That means an attacker who sprays the right bytes into memory passes as a Thales-approved site, and an approved site can tell SConnect to load a plugin.

Pulling that off isn't easy: AI-assisted exploitation made it work roughly 18% of the time. But failed attempts raise nothing the user can see, so an attacker just keeps firing until one lands. Thales patched the Chrome and Apple versions on August 7, then pulled SConnect from Edge on September 13 — 89 000 users still had it, and the researchers can't confirm those copies were removed — and published the CVE on October 1.

SWIFT replaced SConnect with Web Connect in September 2025 and retired SConnect in September this year. Even so, the researchers expect SConnect is still the fallback wherever Web Connect isn't configured, which is why many SWIFT users may still be running it. Update to host 2.16.1.0 and extension 2.16.1.1, then switch to Web Connect.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo