Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

A Critical Flaw in Belgian eID Software Put 2 Million Users at Risk of Identity Theft and Malware Infection

Belgium’s digital identity system has been rocked by a severe security vulnerability that left over two million users exposed to identity theft and malware infection. The flaw, discovered by a security researcher and publicly disclosed at the DEF CON conference, was found in the Connective browser extension used by eight of Belgium’s ten largest banks and more than 60 government agencies.

The software, developed by Nitro Software Belgium, is designed to manage digital identity authentication and execute legally binding electronic signatures. However, it failed to verify which website was attempting to communicate with the user’s computer, allowing any website or embedded online ad to interact directly with the Connective application running on a victim’s machine without their knowledge or permission.

This means that a malicious website could silently read connected electronic ID (eID) and payment card details. Furthermore, attackers could trick users into revealing their eID PIN by triggering official-looking authentication pop-ups that were completely legitimate in appearance but actually phishing attempts. When a user entered their PIN into these fake prompts, the application transmitted it back to the requesting webpage, allowing an attacker to use the PIN to generate unauthorized approval tokens.

These tokens can then be used to forge legally binding electronic signatures whenever the victim’s physical eID card is inserted into a card reader. This would allow attackers to hijack digital identity accounts and carry out malicious transactions on behalf of the user. The vulnerability also carried the risk of spreading like a self-propagating worm by hijacking user credentials to send malicious links to other potential victims.

The researcher who discovered the flaw, James Arnott, found that the software allowed web pages to customize the text inside these dialog boxes without displaying the domain making the request, leaving users with no way to verify whether a prompt was legitimate or a phishing attempt. This made it possible for attackers to trick even the most security-aware users into revealing their sensitive information.

Nitro Software Belgium has since fully remediated the issues and deployed updates to block unauthorized origin requests and secure PIN handling. However, the incident highlights the importance of robust security measures in digital identity systems and the need for regular vulnerability testing to prevent similar attacks in the future.

For users who are still using the Connective browser extension, it is essential to update their software as soon as possible to ensure that they are protected from these vulnerabilities. It is also crucial to be cautious when interacting with online services that use eID authentication and to verify the authenticity of any prompts or requests for sensitive information. By taking these precautions, users can minimize their risk of falling victim to identity theft and malware infection.


Source: SecurityWeek — 2026-08-10