← All stories
● Covered by 1 source · 1 reportHigh impact1 negative

Critical Flaws Found in Belgian eID Software Affecting 2 Million Users

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Connective eID software used by 2M+ Belgians had critical vulnerabilities.
  • Flaws allowed reading eID/payment data, PIN theft, and forged signatures.
  • Remote code execution vulnerability also discovered.
  • Vulnerabilities impacted trust in Belgium's digital identity ecosystem.

Discovery of Critical Vulnerabilities

Security researcher James Arnott, founder of Bay Area Labs, identified severe security vulnerabilities in the Connective digital identity system. This browser extension, developed by Nitro Software Belgium, is utilized by over two million users in Belgium for digital identity authentication and legally binding electronic signatures. The software is integrated into operations for eight of Belgium’s ten largest banks and more than 60 government agencies.

Exploitable Flaws and Impact on User Data

Arnott found that the Connective software failed to verify the origin of communication requests, allowing any website or embedded online advertisement to interact directly with the application on a user's machine without consent. This vulnerability could enable a malicious website to silently extract connected electronic ID (eID) and payment card details. Attackers could also trigger official-looking authentication pop-ups with customizable text, making it impossible for users to distinguish legitimate prompts from phishing attempts, leading to the disclosure of eID PINs.

Forged Signatures and Remote Code Execution

Upon entering a PIN into a compromised prompt, the application would transmit it to the requesting webpage. This allowed an attacker to generate unauthorized approval tokens, enabling the forging of legally binding electronic signatures when a user's physical eID card was inserted into a card reader. Beyond identity theft, a separate remote code execution vulnerability was discovered. This flaw, independent of eID card presence, allowed malicious websites to execute attacker-controlled code at the user level by exploiting how the application processed local files. This drive-by attack could be initiated by tricking a user into downloading a disguised file and visiting a specific webpage.

Broader Ecosystem Implications

The compromise of the eID system significantly undermined the trust model of Belgium’s wider digital ecosystem. This includes government portals such as CSAM.be and third-party identity providers like Itsme. Although these service providers themselves contained no flaws, their reliance on eID signatures meant that an attacker with stolen signing capabilities could register or hijack digital identity accounts, demonstrating the far-reaching consequences of the discovered vulnerabilities.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Security researcher James Arnott discovered critical vulnerabilities in Connective digital identity software, used by over two million people in Belgium for digital identity authentication and electronic signatures. These flaws allowed malicious websites to read eID details, trick users into revealing PINs, forge electronic signatures, and execute remote code, impacting the trust model of Belgium's digital ecosystem.