Falle critiche nell’identità digitale belga Connective: a rischio PIN, firme elettroniche e PC
Vulnerabilities

Illustrative image generated with AI

Critical Vulnerabilities in Belgium’s Connective Digital Identity Platform Put PINs, Electronic Signatures, and PCs at Risk

Critical flaws in Belgium's Connective eID platform expose PINs and electronic signatures to theft and enable code execution. Fixes have been implemented.

Text generated by artificial intelligence, published without human review. AI transparency

An Extension Used by Millions

Security researcher James Arnott, founder of Bay Area Labs, identified serious vulnerabilities in Connective, a browser extension developed by Nitro Software Belgium.

The software is used by more than 2 million people in Belgium, eight of the country’s ten largest banks, and over 60 government agencies. The specific affected versions have not been disclosed, and no CVE identifiers have been assigned.

Nitro completed the fixes in late July, 146 days after the initial report. The researcher received a $200 bounty.

Any Website Could Communicate with the Local Application

Connective did not properly verify the origin of requests coming from the browser. As a result, a malicious website—or even an advertisement embedded in a legitimate page—could communicate with the installed application without explicit user consent.

This access made it possible to silently read information from electronic identity cards and connected payment cards. Web pages could also modify the contents of authentication windows without displaying the actual domain responsible for the request.

This enabled attackers to create convincing prompts designed to steal the eID PIN. Any PIN entered was transmitted to the requesting web page.

With the card physically inserted into the reader, an attacker could use the PIN and available data to generate unauthorized approval tokens and create legally valid electronic signatures. Potential scenarios included identity theft, fraudulent service registration, and account takeover.

Code Execution Was Also Possible

A separate vulnerability was identified that did not require an eID card to be present in the reader. By processing local files, a malicious website could trick Connective into executing attacker-controlled code with the user’s privileges.

The attack required the victim to download a file disguised as an ordinary document and visit a specially crafted webpage. No special permissions were required.

Control of the victim’s credentials could have enabled worm-like propagation, for example by sending malicious links to the victim’s contacts. No real-world exploitation has been reported.

The consequences could have extended to services that rely on eID signatures, including the government portal CSAM.be and the provider Itsme. Neither platform was directly vulnerable; the risk stemmed from the compromise of Connective.

Fixes and Guidance for Users

Nitro blocked requests from unauthorized web origins and added dedicated protections for PIN handling.

Users should:

  • install all updates released by Nitro;
  • verify that the authentication window matches the expected domain and service;
  • never enter their PIN into windows that do not clearly identify the requesting website;
  • avoid files downloaded from unexpected pages or messages.

James Arnott disclosed the findings during the DEF CON conference and published an additional technical analysis.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicseIDConnectivevulnerabilitiesBelgiumPINelectronic signaturessecurity
Back to home