Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

Belgian eID Software Flaws Put Two Million Users at Risk of Identity Theft and Malware Infections

A critical vulnerability has been discovered in the Connective digital identity system, a browser extension used by over two million people in Belgium. The software, developed by Nitro Software Belgium, is employed by eight of the country’s ten largest banks and more than 60 government agencies to manage digital identity authentication and execute legally binding electronic signatures.

Security researcher James Arnott, founder of Bay Area Labs, uncovered severe flaws in the system that allowed malicious websites or embedded online ads to interact directly with the Connective application on a user’s computer without their knowledge or permission. This meant that any website could read connected electronic ID (eID) and payment card details, as well as trick users into revealing their eID PIN by triggering official-looking authentication pop-ups.

The compromise of the eID system had far-reaching consequences for Belgium’s digital ecosystem, including government portals like CSAM.be and third-party identity providers like Itsme. These service providers contained no flaws of their own but relied on eID signatures, which meant that an attacker with stolen signing capabilities could register or hijack digital identity accounts. The risk of identity theft was compounded by the discovery of a remote code execution vulnerability that allowed malicious websites to force the software to execute attacker-controlled code at the user level.

This drive-by attack required no special permissions and carried the risk of spreading like a self-propagating worm, as users’ credentials could be hijacked to send malicious links to other potential victims. Arnott publicly disclosed the findings at DEF CON and released a blog post with additional technical details.

Nitro Software Belgium responded promptly to the initial report by fully remediating the issues 146 days later. The company awarded a $200 bug bounty and deployed updates to block unauthorized origin requests and secure PIN handling, with final security enforcement completed in late July.

The discovery of these critical flaws serves as a reminder of the importance of robust digital identity systems and the need for ongoing vigilance against emerging threats. As more services move online and rely on digital signatures, it’s essential for users to remain aware of potential vulnerabilities and take steps to protect themselves from malicious activity.


Source: SecurityWeek — 2026-08-10