Belgium’s eID Authentication Opens Citizen Accounts to RCE

Belgium’s Electronic Identity System Left Vulnerable to Hackers

A critical flaw in the browser extension used by millions of Belgian citizens to log into sensitive online accounts has left their identities and financial information at risk. The vulnerability, discovered by security researchers, allows hackers to steal personal data, hijack payment cards, and even execute malicious code on users’ computers.

The affected software is called Connective, a signing extension that enables Belgians to use their electronic ID (eID) cards to authenticate with government and banking services online. With over 2 million users and widespread adoption among Belgian institutions, the reach of this vulnerability is significant. The researchers who discovered it have revealed that hackers could use the flaw to steal citizens’ identities with relative ease, hijack payment information, and even perform remote code execution on their computers.

But how does this work? In essence, when a Belgian citizen logs into an online service using their eID, they insert their physical smart card into a reader connected to their computer. The browser extension, Connective, acts as a bridge between the eID app and the website, facilitating authentication without requiring usernames and passwords. However, researchers found that this extension didn’t properly validate which website it was connecting to, relying instead on a generic “activation” token.

This token is meant to ensure that only legitimate websites can interact with the Connective application logic. However, by grabbing an activation token from another trusted site that integrated with Connective, hackers could bypass this security measure and fully interact with a victim’s eID authentication system. From there, they could steal sensitive information or execute malicious code on the user’s computer.

The researchers who discovered this vulnerability have warned that it has serious implications for Belgian citizens’ online security. With over 60 government agencies, eight of the ten largest banks in Belgium, and more than 1,000 enterprises using Connective, the potential damage is substantial. The fact that Nitro Software Belgium, the vendor behind Connective, hasn’t commented on this issue only adds to concerns about their handling of user security.

The discovery of these vulnerabilities serves as a stark reminder of the importance of secure software development practices and the need for robust testing procedures. It also highlights the risks associated with relying on browser extensions to ensure online security. While these tools may provide convenience, they can also introduce significant vulnerabilities if not designed or implemented properly.

For Belgian citizens, this means being more vigilant about their online security. To mitigate these risks, users should monitor their accounts closely for any suspicious activity and consider enabling two-factor authentication whenever possible. Additionally, institutions that rely on Connective should take immediate action to address these vulnerabilities and ensure the security of their users’ sensitive information.


Source: Dark Reading — 2026-08-13