Belgium’s eID Authentication Opens Citizen Accounts to RCE

Belgian Citizens’ eID Accounts Exposed to Remote Code Execution Threats

A severe vulnerability in a widely-used browser extension has compromised the security of millions of Belgian citizens’ electronic ID (eID) accounts. The Connective signing extension, which allows users to authenticate with government and banking services online using their physical smart cards, contains critical flaws that enable hackers to steal identities, payment information, and even execute malicious code on victims’ computers.

The extension, developed by Nitro Software Belgium, is used by over 2 million individuals, including more than 60 government agencies, eight of the country’s largest banks, and over 1,000 enterprises. However, its popularity belies a poor user experience, with an average rating of just 1.7 out of 5 stars on the Chrome Web Store from 542 reviewers.

Researchers at Bay Area Labs discovered the vulnerabilities in the Connective signing system last week at DEF CON 34. The issues allow hackers to steal Belgian citizens’ identities with relative ease, hijack their payment cards, and perform remote code execution (RCE) on their computers. While these flaws have since been patched by Nitro on July 22, the incident highlights significant concerns about the security of browser extensions in general.

The eID login process involves a complex chain of components, including a physical smart card reader, native host software, and the Connective browser extension. In theory, this setup ensures that only individuals with their physical ID cards can access sensitive online accounts. However, researchers found that the last link in this chain – the browser extension and host software – undermines this assumption.

Specifically, the Connective extension fails to verify the website it is connecting to, instead using a generic “activation” token. This enables attackers to easily steal tokens from other websites and use them to access victims’ eID accounts. In essence, hackers can set up a malicious website, adopt another site’s activation token, and fully interact with a victim’s eID authentication system.

The implications are significant: millions of Belgian citizens have been left vulnerable to identity theft, payment card hacking, and RCE attacks through no fault of their own. This incident serves as a stark reminder of the importance of robust security measures in online systems, particularly when it comes to sensitive user data.

As users, we can take steps to protect ourselves from similar threats. When using browser extensions or online services that rely on external authentication methods, ensure you’re dealing with reputable vendors and follow best practices for password management and multi-factor authentication. Most importantly, stay informed about the latest security patches and updates to your software and systems – and be vigilant in reporting suspicious activity to the relevant authorities.


Source: Dark Reading — 2026-08-13