Dark Reading reported on Oct. 2 that Bay Area Labs found a critical flaw in SConnect, a Thales browser extension for hardware-key logins. Dark Reading says the Chrome version has over 1 million users and the tool serves SWIFT and government sites. The researchers say the extension accepts messages from any web page. An oversized, invalid signature makes its check fail silently, yet it reads leftover memory. Attacker-sprayed bytes there can pass as valid, and a malicious DLL (a code file) loads. Bay Area Labs concluded Thales wrote that check itself. Thales patched the Apple and Chrome versions in August, removed the Edge version in September, and published CVE-2026-18397 on Oct. 1, rated 9.4 of 10 on CVSS 4.0.
In the researchers' own tests, an AI-agent-driven attack worked about 18% of the time and took six to 10 seconds. Failed tries showed no visible error. SConnect is now end of life. Thales had not replied to Dark Reading. Worse attacks, such as stolen sessions or money transfers, are unproven because the team had no SWIFT 3SKey. How many users still run SConnect is unknown.
Researcher James Arnott says this once needed nation-state effort, but agents built his exploit. That is his view. Teams that use hardware keys should check which middleware they still run, and whether it is end of life.