Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
Critical security vulnerabilities were discovered in the Connective digital identity system used by over two million users in Belgium, including eight of the country's largest banks and over 60 government agencies. The flaws allowed malicious websites to interact with the software without user consent, potentially exposing eID and payment card details, and tricking users into revealing their eID PIN via phishing-like pop-ups. Attackers could misuse stolen PINs to forge legally binding electronic signatures. Additionally, a remote code execution vulnerability allowed attacker-controlled code execution without requiring an eID card. Nitro Software Belgium fully remediated these issues 146 days after disclosure, deploying updates to block unauthorized requests and secure PIN handling.
AI Analysis
Technical Summary
The Connective digital identity system, a browser extension developed by Nitro Software Belgium and widely used for digital identity authentication and electronic signatures, contained critical vulnerabilities. The software failed to verify the origin of website requests, enabling any website or embedded ad to communicate with the application without user permission. This flaw allowed silent reading of eID and payment card data and phishing attacks via customizable authentication pop-ups lacking domain information, leading to PIN theft. Stolen PINs could be used to generate unauthorized approval tokens to forge electronic signatures when the victim's eID card was inserted. Furthermore, a remote code execution vulnerability existed in the file processing logic, allowing attacker-controlled code execution at the user level without special permissions or requiring an eID card. Nitro Software Belgium addressed these vulnerabilities with updates blocking unauthorized origin requests and securing PIN handling, completing remediation in late July 2026, 146 days after initial reporting. No CVEs have been assigned.
Potential Impact
The vulnerabilities compromised the trust model of Belgium's digital identity ecosystem, affecting major banks and government agencies. Attackers could steal sensitive eID and payment card information, perform phishing attacks to capture PINs, and forge legally binding electronic signatures. The remote code execution flaw allowed attackers to execute arbitrary code on users' machines without elevated privileges, potentially enabling further compromise and self-propagating attacks. These issues risked identity theft, unauthorized transactions, and account hijacking across government portals and third-party identity providers relying on eID signatures.
Mitigation Recommendations
Nitro Software Belgium has fully remediated the vulnerabilities and deployed security updates that block unauthorized origin requests and secure PIN handling. The final security enforcement was completed in late July 2026, 146 days after the initial report. Users and organizations should ensure they have applied the latest updates from Nitro Software Belgium. Since the vendor has addressed the issues with an official fix, no additional immediate mitigation steps are required beyond updating to the patched version.
Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
Description
Critical security vulnerabilities were discovered in the Connective digital identity system used by over two million users in Belgium, including eight of the country's largest banks and over 60 government agencies. The flaws allowed malicious websites to interact with the software without user consent, potentially exposing eID and payment card details, and tricking users into revealing their eID PIN via phishing-like pop-ups. Attackers could misuse stolen PINs to forge legally binding electronic signatures. Additionally, a remote code execution vulnerability allowed attacker-controlled code execution without requiring an eID card. Nitro Software Belgium fully remediated these issues 146 days after disclosure, deploying updates to block unauthorized requests and secure PIN handling.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Connective digital identity system, a browser extension developed by Nitro Software Belgium and widely used for digital identity authentication and electronic signatures, contained critical vulnerabilities. The software failed to verify the origin of website requests, enabling any website or embedded ad to communicate with the application without user permission. This flaw allowed silent reading of eID and payment card data and phishing attacks via customizable authentication pop-ups lacking domain information, leading to PIN theft. Stolen PINs could be used to generate unauthorized approval tokens to forge electronic signatures when the victim's eID card was inserted. Furthermore, a remote code execution vulnerability existed in the file processing logic, allowing attacker-controlled code execution at the user level without special permissions or requiring an eID card. Nitro Software Belgium addressed these vulnerabilities with updates blocking unauthorized origin requests and securing PIN handling, completing remediation in late July 2026, 146 days after initial reporting. No CVEs have been assigned.
Potential Impact
The vulnerabilities compromised the trust model of Belgium's digital identity ecosystem, affecting major banks and government agencies. Attackers could steal sensitive eID and payment card information, perform phishing attacks to capture PINs, and forge legally binding electronic signatures. The remote code execution flaw allowed attackers to execute arbitrary code on users' machines without elevated privileges, potentially enabling further compromise and self-propagating attacks. These issues risked identity theft, unauthorized transactions, and account hijacking across government portals and third-party identity providers relying on eID signatures.
Mitigation Recommendations
Nitro Software Belgium has fully remediated the vulnerabilities and deployed security updates that block unauthorized origin requests and secure PIN handling. The final security enforcement was completed in late July 2026, 146 days after the initial report. Users and organizations should ensure they have applied the latest updates from Nitro Software Belgium. Since the vendor has addressed the issues with an official fix, no additional immediate mitigation steps are required beyond updating to the patched version.
Technical Details
- Classification
- {"confidence":0.65,"severitySource":"stated","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/","fetched":true,"fetchedAt":"2026-08-10T04:56:12.636Z","wordCount":1224}
Threat ID: 6a7959ecbf8831d53906909b
Added to database: 08/10/2026, 04:56:12 UTC
Last enriched: 08/10/2026, 04:56:25 UTC
Last updated: 08/10/2026, 06:05:29 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.