Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies.

eID vulnerabilities

DEF CON — A security researcher has revealed severe, now-resolved security vulnerabilities in the Connective digital identity system, a browser extension used by over two million users in Belgium. 

Developed by Nitro Software Belgium, the software is used by eight of Belgium’s ten largest banks and over 60 government agencies to manage digital identity authentication and execute legally binding electronic signatures.

James Arnott, security researcher and founder of cybersecurity firm Bay Area Labs, discovered that the software failed to verify which website was attempting to communicate with the user’s computer. Because these checks were missing, any website or embedded online ad could interact directly with the Connective application running on a victim’s machine without their knowledge or permission.

According to Arnott, a malicious website could silently read connected electronic ID (eID) and payment card details. Furthermore, attackers could trick users into revealing their eID PIN by triggering official-looking authentication pop-ups. Because the software allowed web pages to customize the text inside these dialog boxes without displaying the domain making the request, users had no way to verify whether a prompt was legitimate or a phishing attempt.

When a user entered their PIN into a prompt, the application transmitted it back to the requesting webpage. An attacker could then use the PIN to generate unauthorized approval tokens to forge legally binding electronic signatures whenever the victim’s physical eID card was inserted into a card reader.

The compromise of the eID system severely impacted the trust model of Belgium’s broader digital ecosystem, including government portals like CSAM.be and third-party identity providers like Itsme. 

Advertisement. Scroll to continue reading.

While these service providers contained no flaws of their own, their reliance on eID signatures meant that an attacker with stolen signing capabilities could register or hijack digital identity accounts.

In addition to identity theft, the researcher uncovered a remote code execution vulnerability that operated independently of whether an eID card was plugged in. By exploiting a flaw in how the application processed files on the local computer, a malicious website could force the software to execute attacker-controlled code at the user level.

An attacker could execute this drive-by attack by tricking a user into downloading a file disguised as a standard document and visiting a webpage. Requiring no special permissions, the flaw also carried the risk of spreading like a self-propagating worm by hijacking user credentials to send malicious links to other potential victims.

Nitro fully remediated the issues 146 days after the initial report and awarded a $200 bug bounty. The company deployed updates to block unauthorized origin requests and secure PIN handling, with final security enforcement completed in late July. No CVEs appear to have been assigned.

Arnott publicly disclosed the findings at DEF CON and released a blog post with additional technical details

UPDATE, August 13, 2026: Nitro provided the following statement:


In early 2026, as part of our bug bounty program an independent security researcher reported vulnerabilities in the browser extension and local signing component that enable Belgian eID signing in Nitro Sign Enterprise Verified and identification in Identity Service. We investigated, developed fixes, and a series of remediations were deployed, with the final hardening enforced in production in July 2026. The vulnerabilities are now resolved.

We found no evidence that any of these vulnerabilities were exploited. The vulnerabilities were reported to the Centre for Cybersecurity Belgium, and we coordinated closely with them throughout the process.

Customers running current versions are protected. The fixes are distributed automatically through the Nitro plugin installer, which delivers the updated SignID component and the current browser extensions. Any customer running an older on-premise deployment can contact our team at [email protected] for assistance in confirming they are up to date.

Related: Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

Related: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

Related: Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Tom Bonos has been named Chief Revenue Officer at Sumo Logic.

Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.

Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.