SConnect was fixed in the app stores 55 days before its CVE, but the desktop host is a separate install
Thales published CVE-2026-18397 on 1 October, 55 days after the SConnect fix reached the Apple store on 7 August, a date the finders also give for Chrome. SWIFT's own notice says the store updates the browser extension only: the desktop host needs a separate install.
By Parminder Kumar Sharma · · 19 min read

55 days between the store fix and the CVE, and what they do not show
Apple's store data puts the SConnect fix on 7 August 2026 at 16:03 UTC. The CVE record for CVE-2026-18397 went public on 1 October at 21:49 UTC. That is 55 days and nearly six hours, derived here from Apple's public lookup interface for the UK Mac App Store and the datePublished field of the CVE.org record. The researchers at Bay Area Labs date the Chrome Web Store fix to the same day, 7 August, and the removal of the Edge copy to 13 September, which is 18 days before the CVE. Those two dates rest on their report alone, because the Chrome listing shows only its latest build, 2.16.1.2, updated 12 August.
What 55 days does not establish is most of what the coverage implies. It does not show that anyone exploited the flaw: CISA's coordinator recorded exploitation as none on 2 October at 19:40 UTC, and the CVE is not in CISA's Known Exploited Vulnerabilities catalogue (version 2026.10.02, read on 4 October). It does not show who was exposed, because no source read for this briefing counts the unpatched. And it is not, by itself, a delay. Fixing first and publishing later is the usual order of coordinated disclosure, and the finders say they reported the flaw to Thales on 29 June, 94 days before the CVE. Earlier briefings on the MCP Python SDK and on Zimbra showed the same shape: a fix that predates its paperwork.
The gap is worth reading for a narrower reason. SConnect is two programs: a browser extension, which the browser's store delivers, and a native host, a desktop program with its own installer. Dark Reading's account says Thales patched SConnect in the app stores in August. That is true of the extension. SWIFT's own notice says the desktop half needs a separate install, and the CVE record places the flaw in that desktop half.
How each date was checked
Six of the ten dates below can be read from a first-party source. Four rest on the finders' own timeline, which is their account of a private exchange with Thales.
Each date, where it comes from and how it was checked. UTC where the source gives a time. Read 4 October 2026.
- Date (2026)
- 29 Jun
- Event
- Reported to Thales PSIRT
- Source and check
- Bay Area Labs report only. Not independently checkable.
- Date (2026)
- 3 Jul
- Event
- Thales confirms; the report says a CVE was reserved
- Source and check
- Report only. The CVE.org record shows the ID reserved on 30 Jul, 27 days later.
- Date (2026)
- 30 Jul
- Event
- CVE ID reserved
- Source and check
- CVE.org record, dateReserved 14:55 UTC.
- Date (2026)
- 4 Aug
- Event
- Thales compatibility page for host 2.16.1.0 last updated
- Source and check
- Thales SConnect FAQ, read directly: Last Updated 2026/8/4.
- Date (2026)
- 7 Aug
- Event
- Apple: two Safari builds at version 2.16.1
- Source and check
- Apple lookup, UK storefront: released 16:03 and 16:04 UTC. The release notes list native host hardening, security enhancements and SDK version matching, and name no vulnerability.
- Date (2026)
- 7 Aug
- Event
- Chrome Web Store fix
- Source and check
- Report only. The listing now shows 2.16.1.2, updated 12 Aug.
- Date (2026)
- 12 Aug
- Event
- Chrome lists 2.16.1.2
- Source and check
- Listing read 4 Oct. An Internet Archive capture of 2 Oct, 17:36 UTC, shows the same version and date.
- Date (2026)
- 13 Sep
- Event
- Edge copy removed
- Source and check
- Report only. A search of Edge Add-ons on 4 Oct finds no SConnect, which is consistent with removal and is not proof.
- Date (2026)
- 30 Sep
- Event
- SWIFT's sunset of SConnect for 3SKey tokens
- Source and check
- SWIFT Web Connect page, read directly.
- Date (2026)
- 1 Oct
- Event
- CVE published
- Source and check
- CVE.org: 21:49 UTC. NVD lists it at 22:17 UTC.
| Date (2026) | Event | Source and check |
|---|---|---|
| 29 Jun | Reported to Thales PSIRT | Bay Area Labs report only. Not independently checkable. |
| 3 Jul | Thales confirms; the report says a CVE was reserved | Report only. The CVE.org record shows the ID reserved on 30 Jul, 27 days later. |
| 30 Jul | CVE ID reserved | CVE.org record, dateReserved 14:55 UTC. |
| 4 Aug | Thales compatibility page for host 2.16.1.0 last updated | Thales SConnect FAQ, read directly: Last Updated 2026/8/4. |
| 7 Aug | Apple: two Safari builds at version 2.16.1 | Apple lookup, UK storefront: released 16:03 and 16:04 UTC. The release notes list native host hardening, security enhancements and SDK version matching, and name no vulnerability. |
| 7 Aug | Chrome Web Store fix | Report only. The listing now shows 2.16.1.2, updated 12 Aug. |
| 12 Aug | Chrome lists 2.16.1.2 | Listing read 4 Oct. An Internet Archive capture of 2 Oct, 17:36 UTC, shows the same version and date. |
| 13 Sep | Edge copy removed | Report only. A search of Edge Add-ons on 4 Oct finds no SConnect, which is consistent with removal and is not proof. |
| 30 Sep | SWIFT's sunset of SConnect for 3SKey tokens | SWIFT Web Connect page, read directly. |
| 1 Oct | CVE published | CVE.org: 21:49 UTC. NVD lists it at 22:17 UTC. |
The Apple row matters for a practical reason. A defender who read the store's release notes on 7 August would have seen "security enhancements", not a critical remote code execution fix. The CVE, the score and the word critical arrived 55 days later. A team that waits for a CVE before acting on an update to a security product has no ticket for those 55 days.
What the CVE record says, and who said it
The record carries two voices. Thales's product security team, Thales PSIRT, is the CNA, the body that assigned the ID, and it wrote the description, the 9.4 score and the weakness list. The second voice, CISA's ADP container (organisation ID 134c704f-9b21-4f2e-91b3-4a467353bcc0, which is CISA and not the vendor), adds only a triage entry. NVD carries no score of its own: its status was Deferred when read, and it lists Thales's score as secondary.
What CVE-2026-18397 carries, from the CVE.org record and the NVD API, read 4 October 2026
- Field
- Title
- Value
- SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability
- Assigned by
- Thales PSIRT (CNA)
- Field
- Affected
- Value
- SConnect, every version from 0 up to but not including 2.16.1.0. The record gives no split by platform or component, though its description names the native host.
- Assigned by
- Thales PSIRT
- Field
- Score
- Value
- CVSS 4.0 base 9.4, Critical. Network, low complexity, no privileges, passive user interaction, high impact on the vulnerable and the subsequent systems.
- Assigned by
- Thales PSIRT
- Field
- Weaknesses
- Value
- CWE-347 improper verification of a cryptographic signature, CWE-130 length parameter inconsistency, CWE-457 use of an uninitialised variable, CWE-252 unchecked return value.
- Assigned by
- Thales PSIRT
- Field
- Triage
- Value
- SSVC: exploitation none, automatable no, technical impact total, stamped 2 Oct 2026 19:40 UTC.
- Assigned by
- CISA coordinator, in the CISA-ADP container
- Field
- Status
- Value
- NVD: Deferred, last modified 2 Oct 20:17 UTC. Not in the KEV catalogue.
- Assigned by
- NVD; CISA
- Field
- Reference
- Value
- One link, Thales's general PSIRT page, tagged vendor advisory.
- Assigned by
- Thales PSIRT
| Field | Value | Assigned by |
|---|---|---|
| Title | SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability | Thales PSIRT (CNA) |
| Affected | SConnect, every version from 0 up to but not including 2.16.1.0. The record gives no split by platform or component, though its description names the native host. | Thales PSIRT |
| Score | CVSS 4.0 base 9.4, Critical. Network, low complexity, no privileges, passive user interaction, high impact on the vulnerable and the subsequent systems. | Thales PSIRT |
| Weaknesses | CWE-347 improper verification of a cryptographic signature, CWE-130 length parameter inconsistency, CWE-457 use of an uninitialised variable, CWE-252 unchecked return value. | Thales PSIRT |
| Triage | SSVC: exploitation none, automatable no, technical impact total, stamped 2 Oct 2026 19:40 UTC. | CISA coordinator, in the CISA-ADP container |
| Status | NVD: Deferred, last modified 2 Oct 20:17 UTC. Not in the KEV catalogue. | NVD; CISA |
| Reference | One link, Thales's general PSIRT page, tagged vendor advisory. | Thales PSIRT |
Two things stand out. First, the only reference in the record is a general page. When read on 4 October the Thales PSIRT page carried no SConnect advisory. Thales's dedicated advisories page answered with a bot check, which was not bypassed, and an Internet Archive capture of 15 September lists two advisories from May 2025 and nothing on SConnect. No Thales advisory text could therefore be read for this briefing. The fixed versions below come from SWIFT's page and from the affected range in the record.
Second, the SSVC entry is a judgement at a point in time. CISA's SSVC guide defines exploitation none as no evidence of active exploitation and no public proof of concept, and says answers should be time-stamped because the state changes. It defines automatable as whether an attacker can reliably automate the steps from reconnaissance to exploitation. CISA's coordinator answered no. The finders describe a visit-a-page attack that completed end to end in six to ten seconds in their testing. Both can be true: one is about reliable automation at scale, the other about a demonstration. Neither is evidence about what has happened in the wild.
Who is telling us what
Bay Area Labs describes itself as an independent security company. Its product is Am I Being Pwned?, a browser extension security service for organisations, and the SConnect report is published on that product's blog, where the extension catalogue also rates SConnect high risk with a note that its page is AI-generated and may contain errors. The finders therefore have a commercial interest in extension risk being taken seriously. That does not make the findings wrong. The CVE record, SWIFT's notice and Thales's own FAQ independently confirm the flaw, the fixed version and the update path.
What rests on the report alone: the 29 June report date, the 7 August Chrome date, the 13 September Edge removal, the 89,000 Edge users at removal, the statement that updated extensions can no longer reach the old host, and the six to ten second demonstration. The finders also had no 3SKey or eID to test with, and they tested only the Chrome Web Store build. Their own text says this "is not a story of incompetence"; coverage quotes harsher language. This briefing does not grade Thales's engineering. It grades what the record establishes. Dark Reading reported on 2 October that Thales had not yet responded to its request for comment, and no Thales statement was found.
Where the flaw sat in the chain
The shape is the one the finders flag as risky: any site, then an extension, then a native host. A page sends a message to the extension. The extension, whose content script runs in every frame, forwards it with the page's origin to a native host, a desktop program outside the browser's sandbox. The host decides whether the site is approved and, if so, lets the page drive the token and install add-ons. According to the report, approval depends on a token, signed by Thales, that the host fetches from the site and verifies.
The CVE record's wording is an "unrestricted messaging interface" between an attacker-controlled web page and the native host, combined with cryptographic and memory handling weaknesses that let malicious input bypass security checks. The report puts the weakness in an in-house implementation of the signature check that mishandled a failure case, and says that once the check was defeated the same routine also vouched for an add-on, which the host then loaded into its own process. This briefing stops at that level of detail on purpose.
What the finders showed was code running inside the signed Thales host process on the workstation, reached from a web page, and invisible to the user in their account. Thales's FAQ describes an Origin Access dialog that asks the user to allow a site that has not been approved before. Whether that dialog would have appeared in the demonstrated flow is not stated. They had no 3SKey or eID, so they did not test what an attacker could do with a token present. The researcher told Dark Reading that relaying challenges to sign documents, stealing a session or moving money could follow, and that he could not prove it for lack of a token. That is a hypothesis from the finder, not a finding.
Hardware MFA protects the credential, not the program that brokers it
A hardware token is a control on a credential: it keeps a private key out of reach and makes a stolen password worthless. Nothing in this story defeats that. The token was not in the path of what was shown. What was shown was a web page talking a desktop program into running code, and the weak point was the software that sits between the page and the token. A FIDO-grade authenticator would be the same kind of control on the same part of the chain: it vouches for the credential, not for whatever software brokers it. Nothing read here describes 3SKey or the national eID cards as FIDO2 devices. SWIFT calls 3SKey "a multi-bank and multi-network personal digital identity solution".
What code on the workstation can do next is not shown. As inference, a compromised host or a stolen session sits after the token has done its job, so the token cannot stop either, and the approval a token gives is only as trustworthy as the machine asking for it. That is why a treasury team should care about the workstation as much as the token. Two earlier briefings make the same point from other directions: a rogue external MFA provider can simply ask for the password again, and device code phishing is a phish that MFA cannot stop.
The native host: who updates it, according to the people who ship it
This is the practical crux for defenders, and the primaries speak to it more clearly than the coverage does. Thales's own FAQ describes installing SConnect as separate steps, the extension from the browser's store and then a separate extension host installer, and describes uninstalling as two steps as well, with the host removed from the operating system's list of installed programs.
Stated and not stated about the desktop host, from SWIFT's pages, Thales's FAQ, the CVE record, the CISA entries, the Apple and Chrome listings and the Bay Area Labs report. Read 4 October 2026.
- Question
- Does the store update reach the desktop host?
- Stated
- No automatic path is described. SWIFT tells users to download host 2.16.1.0 and run its installer. Thales's FAQ lists the host as its own installed program.
- Not stated
- Any automatic or silent host update.
- Question
- New extension, old host?
- Stated
- SWIFT: SConnect is disabled until the host is upgraded. The report: updated extensions "no longer were able to communicate with the old native host".
- Not stated
- Whether the old host stays on disk, and whether anything else can still reach it.
- Question
- Which extension copies got the fix?
- Stated
- Chrome and Edge users through the Chrome store (SWIFT). Two Safari builds on 7 Aug (Apple). Firefox users install by hand (SWIFT).
- Not stated
- Edge installs that predate the 13 Sep removal: the report "cannot confirm" they were uninstalled. Any platform beyond the tested Chrome build.
- Question
- Which versions are affected?
- Stated
- Below 2.16.1.0 (CVE record). Version 2.16.0 and earlier (SWIFT). 2.16.0.0 demonstrated (report).
- Not stated
- A split by platform or component. A statement on the Safari, macOS or Linux hosts.
- Question
- Any sign of use against victims?
- Stated
- CISA triage: exploitation none (2 Oct). Not in the KEV catalogue (4 Oct). The report names no victim.
- Not stated
- Telemetry from Thales, SWIFT or any bank. Indicators of compromise. How many hosts are still unpatched.
- Question
- Has Thales said anything?
- Stated
- A host download page, and a CVE record that credits the finder.
- Not stated
- A dated advisory. Any statement on Edge copies. A comment to the press: none had arrived when Dark Reading published on 2 Oct.
| Question | Stated | Not stated |
|---|---|---|
| Does the store update reach the desktop host? | No automatic path is described. SWIFT tells users to download host 2.16.1.0 and run its installer. Thales's FAQ lists the host as its own installed program. | Any automatic or silent host update. |
| New extension, old host? | SWIFT: SConnect is disabled until the host is upgraded. The report: updated extensions "no longer were able to communicate with the old native host". | Whether the old host stays on disk, and whether anything else can still reach it. |
| Which extension copies got the fix? | Chrome and Edge users through the Chrome store (SWIFT). Two Safari builds on 7 Aug (Apple). Firefox users install by hand (SWIFT). | Edge installs that predate the 13 Sep removal: the report "cannot confirm" they were uninstalled. Any platform beyond the tested Chrome build. |
| Which versions are affected? | Below 2.16.1.0 (CVE record). Version 2.16.0 and earlier (SWIFT). 2.16.0.0 demonstrated (report). | A split by platform or component. A statement on the Safari, macOS or Linux hosts. |
| Any sign of use against victims? | CISA triage: exploitation none (2 Oct). Not in the KEV catalogue (4 Oct). The report names no victim. | Telemetry from Thales, SWIFT or any bank. Indicators of compromise. How many hosts are still unpatched. |
| Has Thales said anything? | A host download page, and a CVE record that credits the finder. | A dated advisory. Any statement on Edge copies. A comment to the press: none had arrived when Dark Reading published on 2 Oct. |
Three practical consequences follow, and the first two are why the gap matters.
A stale host beside a current extension fails closed. According to SWIFT and the report, SConnect stops working rather than carrying on with the old host. That protects the browsers that updated. It leaves the extension copies that did not: Firefox installs, an Edge copy that was never removed and, as inference, managed or offline browsers where extension updates are held back. The primaries do not list that last group. It is a place to look, not a finding.
SWIFT's own installer button starts a workstation inside the affected range. On 4 October, SWIFT's token software page says the Install SConnect button "installs SConnect Host 2.13 and provides a link to update to SConnect Host 2.16.1.0". Version 2.13 is below the CVE's fixed version. A machine built from that button stays there until someone follows the link.
Removing the extension removes only the browser half. Thales's FAQ gives host removal as a separate step. An endpoint that dropped the extension may still carry a host below 2.16.1.0. Whether that host is reachable without an extension is not stated, but it is an affected version on the record and the one thing no store will ever update.
End of life is SWIFT's date, and the same vendor's replacement is not assessed
Dark Reading says SConnect reached end of life the month before it wrote. SWIFT's pages say something narrower. The SConnect page says SWIFT "plans to end support for SConnect in September 2026". The Web Connect page says "The vendor has announced the sunset of SConnect on 30 September 2026", after which SWIFT will not support SConnect with 3SKey tokens. That is a date for one use. Thales's updater page still offers eGovernment and eBanking variants beside the SWIFT one, and the Chrome listing was updated on 12 August. The CVE was published one day after SWIFT's date. The sources say nothing about a connection, so treat it as a coincidence of dates.
SWIFT's advice complicates the obvious fix. Its Web Connect page says that if you use SConnect to sign in to a treasury or bank application, do not uninstall it, because the application provider will say when it has moved to Web Connect, and the two can sit on one machine. So removal needs the provider's word, and the migration target is a product from the same vendor: the page names it Gemalto Web Connect and says installing it needs administrator rights. No source read here assesses it. A replacement is a migration plan, not a finding about its safety.
Who uses it, as far as the primaries go
Where SConnect use is evidenced, with the kind of source. Read 4 October 2026.
- Context
- SWIFT 3SKey portal; treasury and bank applications
- What the source says
- SConnect is "a browser extension that can be used to access the 3SKey portal"; do not uninstall it if a treasury or bank application uses it.
- Source
- SWIFT help pages, first-party
- Context
- Qatar national authentication
- What the source says
- An SConnect FAQ is hosted on a Qatar government domain, nas.gov.qa.
- Source
- Qatar page; named by the report
- Context
- Swedish Tax Agency
- What the source says
- Its page on the e-ID on its ID card says users need the SConnect browser plug-in.
- Source
- Agency page; Dark Reading names the agency
- Context
- Banking and insurance
- What the source says
- The report names BNP Paribas corporate banking, banks using Gemalto Ezio card readers and, "potentially historically", AG Insurance.
- Source
- Report only, not checked
- Context
- Product variants
- What the source says
- Thales's updater offers eGovernment, eBanking and eBanking Swift variants.
- Source
- Thales updater page
- Context
- How many users
- What the source says
- Chrome: 1,000,000 shown. Edge: 89,000 at removal. Apple: no count.
- Source
- Chrome listing; report
| Context | What the source says | Source |
|---|---|---|
| SWIFT 3SKey portal; treasury and bank applications | SConnect is "a browser extension that can be used to access the 3SKey portal"; do not uninstall it if a treasury or bank application uses it. | SWIFT help pages, first-party |
| Qatar national authentication | An SConnect FAQ is hosted on a Qatar government domain, nas.gov.qa. | Qatar page; named by the report |
| Swedish Tax Agency | Its page on the e-ID on its ID card says users need the SConnect browser plug-in. | Agency page; Dark Reading names the agency |
| Banking and insurance | The report names BNP Paribas corporate banking, banks using Gemalto Ezio card readers and, "potentially historically", AG Insurance. | Report only, not checked |
| Product variants | Thales's updater offers eGovernment, eBanking and eBanking Swift variants. | Thales updater page |
| How many users | Chrome: 1,000,000 shown. Edge: 89,000 at removal. Apple: no count. | Chrome listing; report |
The report says outright that it does not know how many banks used SConnect. Neither does any other source read here. Bay Area Labs and Dark Reading call SConnect a main route into the SWIFT banking system; the SWIFT pages read describe the 3SKey portal and applications that use 3SKey tokens. Whether those are the same thing for a given bank is a question for that bank.
The UK angle: no UK name in the primaries, UK-named sibling extensions on the same store
No source read names a UK bank, treasury team or public body as an SConnect user. Both Apple builds are listed on the UK storefront, which says nothing about use. What a UK security lead can say today is narrower: the exposure is whichever endpoints carry the extension and the host, and the only way to know is to look.
There is one more place to look. A Chrome Web Store search for Gemalto Web Signer on 4 October returns extensions published under Thales names and titled for UK banks.
Thales-published Web Signer extensions with UK bank names on the Chrome Web Store, read 4 October 2026. A different product line from SConnect.
- Listing
- Gemalto Web Signer for NatWest
- Version and update date
- 2.4.89, 16 July 2026
- Users shown
- None shown
- Listing
- Gemalto Web Signer for Lloyds Banking Group
- Version and update date
- 2.4.92, 2 September 2026
- Users shown
- None shown
- Listing
- Web Signer for Barclays
- Version and update date
- 2.3.1.7, 5 September 2026
- Users shown
- 100,000
- Listing
- Gemalto Web Signer for Sign online CYBG
- Version and update date
- 2.3.1.40, 22 January 2026
- Users shown
- None shown
| Listing | Version and update date | Users shown |
|---|---|---|
| Gemalto Web Signer for NatWest | 2.4.89, 16 July 2026 | None shown |
| Gemalto Web Signer for Lloyds Banking Group | 2.4.92, 2 September 2026 | None shown |
| Web Signer for Barclays | 2.3.1.7, 5 September 2026 | 100,000 |
| Gemalto Web Signer for Sign online CYBG | 2.3.1.40, 22 January 2026 | None shown |
No source read ties these to CVE-2026-18397, and none says whether they carry a native component. The finders say they have more digital signing extensions with similar weaknesses than they can report, and they name none. The listings are a prompt to inventory and to ask the vendor, not a finding. For a suspected compromise, the NCSC runs a cyber incident reporting service, and a regulated firm should tell its supervisor.
What to do, in the order worth doing it
Take this with you
Treasury and government portal endpoints, in order
- Inventory both halves on every endpoint that touches SWIFT 3SKey, bank portals or government portals: the SConnect extension (Chrome Web Store ID mjhbkkaddmmnkghdnnmkjcgpphnopnfk, the two Safari apps from Thales DIS Czech Republic s.r.o., any Firefox or Edge copy) and the SConnect Host entry in the installed programs list. Record both versions. Include user-space installs, virtual desktop images and gold builds.
- Confirm the fixed versions: host 2.16.1.0 or later and extension 2.16.1.1 or later, per SWIFT. Treat anything below 2.16.1.0 as affected, per the CVE record. Chrome listed 2.16.1.2 on 4 October 2026.
- Find extension copies that cannot update: Firefox installs, extension versions pinned or blocked by policy, offline or non-persistent images. Update or remove these first, because an old extension is the route to an old host.
- Check for an Edge copy and compare its version with the Chrome listing. No Thales statement on Edge installs already in place was found, and the finders could not confirm they were removed.
- Ship your own host installer at 2.16.1.0 or later. SWIFT's Install SConnect button lays down version 2.13 first, so do not build new workstations from it.
- Restrict who may install extensions and native hosts. Allow-list extensions by ID. In Chrome and Edge, set the native messaging block list to deny all hosts and allow only the host you name, and disable user-level native messaging hosts so that only system-level installs are honoured. Both browsers document these policies.
- Review what each token or signing extension may talk to. The researchers' catalogue lists SConnect 2.16.0.0 as declaring access to all sites, to tab details and to native messaging. Ask every vendor of a token or signing extension which origins it accepts and how its host verifies them.
- Treat treasury and government portal workstations as a tier of their own: a dedicated browser or profile used only for those portals, no general browsing or mail, extension and host allow-lists, application control on the host's folder, and outbound access limited to the portals. The demonstrated attack needed only a page visit.
- Do not uninstall SConnect on a machine whose treasury or bank application still depends on it until the application provider confirms its move to Web Connect. SWIFT says so. Update it instead, and ask the provider for its date.
- Hunt, then report. Look back as far as your logs allow for the SConnect host process starting child processes or writing libraries outside its install folder. That is a hunt idea, not an indicator: none has been published. Report a suspected compromise to the NCSC, to your supervisor if you have one, to your bank and to SWIFT.
The question that exposes the gap
The browsers were told on 7 August, by a store note that said "security enhancements". The desktop programs were told, if at all, by a SWIFT notice that users had to find, a ZIP they had to download and an EXE that somebody had to be allowed to run. Which of your treasury workstations is running SConnect host 2.16.1.0 today, and who told you?
Sources
- PrimaryThe CVE.org record for CVE-2026-18397, read in full: CNA, dates reserved and published, description, affected range, CVSS 4.0 score and vector, weaknesses, credit, and the CISA-ADP SSVC containerCVE Program, record assigned by Thales PSIRT as CNAaccessed 2026-10-04
- PrimaryThe NVD record for the same CVE, read through the NVD API at 10:58 UTC on 4 October 2026: status Deferred, last modified 2 October, Thales score carried as secondaryNIST National Vulnerability Databaseaccessed 2026-10-04
- PrimaryThe finders' own report of 2 October 2026, read in full: the flow, the timeline, the affected version, the Edge user count and the statement about the updated extension. Technical exploitation detail deliberately not reproducedBay Area Labs (Am I Being Pwned?)accessed 2026-10-04
- PrimarySWIFT's SConnect page, read in a browser: what SConnect is, the critical update to host 2.16.1.0 and extension 2.16.1.1, how the extension and host are updated, and the end of support planSWIFT 3SKey helpaccessed 2026-10-04
- PrimarySWIFT's Web Connect page: the sunset date of 30 September 2026, the advice not to uninstall SConnect, and the replacementSWIFT 3SKey helpaccessed 2026-10-04
- PrimarySWIFT's token software installation page: the Install SConnect button that installs host 2.13 and links to 2.16.1.0SWIFT 3SKey helpaccessed 2026-10-04
- PrimaryThe 3SKey home page: how 3SKey describes itself and its September 2026 notice that Web Connect replaces SConnectSWIFT 3SKeyaccessed 2026-10-04
- PrimaryThales's official SConnect FAQ: separate extension and extension host installation, two-step uninstall, the Update Native Host dialog, the Origin Access dialog, and the compatibility page for 2.16.1.0 last updated 2026/8/4Thales Groupaccessed 2026-10-04
- PrimaryThales's official SConnect updater page: eGovernment, eBanking and eBanking Swift variants and the instruction to download the host from SwiftThales Groupaccessed 2026-10-04
- PrimaryThe SConnect listing read on 4 October 2026: version 2.16.1.2, updated 12 August 2026, 1,000,000 users, developer Thales DIS Czech Republic s.r.o.Google Chrome Web Storeaccessed 2026-10-04
- PrimaryA capture of the Chrome Web Store listing at 17:36 UTC on 2 October 2026, showing the same version, update date and user countInternet Archiveaccessed 2026-10-04
- PrimaryApple's public lookup interface for the UK storefront: two Safari web extension apps by Thales DIS Czech Republic s.r.o., version 2.16.1, current version released 7 August 2026 at 16:03 and 16:04 UTC, with release notesAppleaccessed 2026-10-04
- PrimaryA search of the Edge Add-ons store for sconnect on 4 October 2026, which returned three unrelated extensionsMicrosoft Edge Add-onsaccessed 2026-10-04
- PrimaryThe Known Exploited Vulnerabilities catalogue, version 2026.10.02 released 2 October 2026, 1,733 entries: CVE-2026-18397 is not listedCISAaccessed 2026-10-04
- PrimaryThe CISA SSVC guide, used for the definitions of the exploitation and automatable values and the advice to time-stamp answersCISAaccessed 2026-10-04
- PrimaryThales's PSIRT page, the only reference in the CVE record: a general page that carries no SConnect advisoryThales Groupaccessed 2026-10-04
- PrimaryA capture of Thales's product security advisories page from 15 September 2026, listing two advisories dated May 2025 and none for SConnect. The live page answers with a bot check, which was not bypassedInternet Archiveaccessed 2026-10-04
- PrimaryAn SConnect FAQ page hosted on a Qatar government domain, supporting the report's statement that Qatar's national authentication system uses SConnectQatar National Authentication Systemaccessed 2026-10-04
- PrimaryThe agency's page on the e-ID carried by its ID card, which says users need the SConnect browser plug-inSkatteverket (Swedish Tax Agency)accessed 2026-10-04
- PrimaryA store search for Gemalto Web Signer on 4 October 2026, returning Thales-published Web Signer extensions named for UK banks, with version, update date and user figures read from each listingGoogle Chrome Web Storeaccessed 2026-10-04
- PrimaryChrome's documentation of the native messaging block list, allow list and user-level hosts policiesGoogle Chrome Enterpriseaccessed 2026-10-04
- PrimaryMicrosoft Edge's documentation of the equivalent native messaging policiesMicrosoft Learnaccessed 2026-10-04
- PrimaryThe NCSC's service for reporting a cyber security incidentNational Cyber Security Centreaccessed 2026-10-04
- PrimaryThe finders' own description of themselves and of their product, Am I Being Pwned?, a browser extension security service for organisationsBay Area Labsaccessed 2026-10-04
- Reported byNews coverage of 2 October 2026 by Nate Nelson, the pointer to the story. Its claims were checked against the primaries above; the researcher's speculation about wider attacks and the statement that Thales had not responded rest on this article aloneDark Readingaccessed 2026-10-04


