SWIFT Banking & Government Middleware Enables RCE

Critical Vulnerability in Government and Banking Middleware Exposes Users to Remote Code Execution Attacks

A critical vulnerability has been discovered in SConnect, a hardware authentication program used by over a million users worldwide to access sensitive government and financial systems. The flaw, which allows attackers to perform remote code execution (RCE) attacks in mere seconds, has significant implications for organizations that rely on this middleware.

SConnect is a browser extension and desktop program combination that facilitates communication between hardware tokens and websites. It’s used by major national governments, such as Qatar’s Tawtheeq and Sweden’s Skatteverket, as well as various banking and insurance portals. Notably, it’s also one of the primary methods for accessing the SWIFT banking system, which supports the global financial apparatus.

The vulnerability, discovered by researchers at Bay Area Labs, allows attackers to exploit a weakness in SConnect’s browser extension. The program accepts messages from any webpage or embedded iframe, including malicious ones, and checks if they possess a valid RSA digital signature from Thales Group, its vendor. However, the app developers failed to protect against oversized signatures, which can cause the calculation to fail without writing anything to memory. In this case, SConnect still reads the stale buffer, allowing attackers to fake signature results and deceive the software into accepting them as valid.

Bay Area Labs was able to successfully exploit this vulnerability about 18% of the time using AI agents, with no visible error alerts to users that they were under attack. The researchers warned that potential attack scenarios could get worse, highlighting the need for immediate action by affected organizations.

Thales Group has since patched SConnect on the Apple App Store and Chrome Web Store in August and removed it from Microsoft Edge in September. The company assigned a “critical” 9.4 out of 10 rating to the vulnerability in the Common Vulnerability Scoring System (CVSS) 4.0 scale, emphasizing the urgency for users to update their instances as soon as possible.

This vulnerability serves as a reminder that even with robust security measures in place, there are always vulnerabilities waiting to be exploited. Organizations relying on SConnect and similar middleware should prioritize patching these weaknesses to avoid potential attacks. Moreover, it’s essential to stay vigilant and monitor systems for any signs of suspicious activity.

In light of this discovery, users are advised to update their SConnect instances immediately and remain cautious when accessing sensitive systems. This incident underscores the importance of ongoing security monitoring and maintenance to prevent such vulnerabilities from being exploited.


Source: Dark Reading — 2026-10-02