Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

0
Critical
Vulnerability
Published: 08/10/2026 (08/10/2026, 04:44:32 UTC)
Source: SecurityWeek

Description

Critical security vulnerabilities were discovered in the Connective digital identity system used by over two million users in Belgium, including eight of the country's largest banks and over 60 government agencies. The flaws allowed malicious websites to interact with the software without user consent, potentially exposing eID and payment card details, and tricking users into revealing their eID PIN via phishing-like pop-ups. Attackers could misuse stolen PINs to forge legally binding electronic signatures. Additionally, a remote code execution vulnerability allowed attacker-controlled code execution without requiring an eID card. Nitro Software Belgium fully remediated these issues 146 days after disclosure, deploying updates to block unauthorized requests and secure PIN handling.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 04:56:25 UTC

Technical Analysis

The Connective digital identity system, a browser extension developed by Nitro Software Belgium and widely used for digital identity authentication and electronic signatures, contained critical vulnerabilities. The software failed to verify the origin of website requests, enabling any website or embedded ad to communicate with the application without user permission. This flaw allowed silent reading of eID and payment card data and phishing attacks via customizable authentication pop-ups lacking domain information, leading to PIN theft. Stolen PINs could be used to generate unauthorized approval tokens to forge electronic signatures when the victim's eID card was inserted. Furthermore, a remote code execution vulnerability existed in the file processing logic, allowing attacker-controlled code execution at the user level without special permissions or requiring an eID card. Nitro Software Belgium addressed these vulnerabilities with updates blocking unauthorized origin requests and securing PIN handling, completing remediation in late July 2026, 146 days after initial reporting. No CVEs have been assigned.

Potential Impact

The vulnerabilities compromised the trust model of Belgium's digital identity ecosystem, affecting major banks and government agencies. Attackers could steal sensitive eID and payment card information, perform phishing attacks to capture PINs, and forge legally binding electronic signatures. The remote code execution flaw allowed attackers to execute arbitrary code on users' machines without elevated privileges, potentially enabling further compromise and self-propagating attacks. These issues risked identity theft, unauthorized transactions, and account hijacking across government portals and third-party identity providers relying on eID signatures.

Mitigation Recommendations

Nitro Software Belgium has fully remediated the vulnerabilities and deployed security updates that block unauthorized origin requests and secure PIN handling. The final security enforcement was completed in late July 2026, 146 days after the initial report. Users and organizations should ensure they have applied the latest updates from Nitro Software Belgium. Since the vendor has addressed the issues with an official fix, no additional immediate mitigation steps are required beyond updating to the patched version.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.65,"severitySource":"stated","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/","fetched":true,"fetchedAt":"2026-08-10T04:56:12.636Z","wordCount":1224}

Threat ID: 6a7959ecbf8831d53906909b

Added to database: 08/10/2026, 04:56:12 UTC

Last enriched: 08/10/2026, 04:56:25 UTC

Last updated: 08/10/2026, 06:05:29 UTC

Views: 26

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses