Illustrative image generated with AI
Critical Flaw in Belgian eID Could Let a Malicious Website Reach a Victim’s Computer
The Connective signing extension links the browser to the local software required to use Belgian electronic identity cards on government and banking
Text generated by artificial intelligence, published without human review. AI transparency
The Component Involved in ID Card Authentication
The Connective signing extension links the browser to the local software required to use Belgian electronic identity cards on government and banking portals.
The process requires four elements:
- an electronic identity card;
- a USB smart card reader;
- host software installed on the computer;
- the Connective browser extension.
In 2021, Nitro Software Belgium said the technology had been adopted by more than 60 government agencies and departments, eight of Belgium’s ten largest banks, and over 1,000 companies. The extension also has more than 2 million users on the Chrome Web Store, where it holds an average rating of 1.7 out of 5 based on 542 reviews.
A Generic Token Replaced the Website’s Identity
The vulnerability stemmed from the way the extension verified which website was authorized to communicate with the host software.
Instead of sending the address of the portal actually being visited, the extension used a generic “activation” token. Other websites integrating Connective could also retrieve the value.
Researchers, including James Arnott, founder of Bay Area Labs, demonstrated that a token copied from a Belgian digital administration platform could be reused. A malicious website could therefore impersonate a legitimate integration and interact with the victim’s eID system.
The flaw was disclosed recently at DEF CON 34. The issues were reportedly fixed on July 22.
Personal Data, Payments, and Executable Code at Risk
A successful attack could have enabled the theft of data stored on the card and the user’s identifying information. An attacker could also have compromised the victim’s digital identity or redirected their payment cards.
The most serious impact, however, involved the remote execution of code on the local computer. In practice, a malicious web page could have exploited the connection to the host software to access resources normally available only to authorized government or banking services.
Users who rely on eID authentication for public portals, banks, and other services compatible with Connective were therefore exposed.
No CVSS score or CVE identifier has been assigned.
What Users and Organizations Should Do
The vulnerabilities were reportedly fixed on July 22, but the affected versions, fixed release numbers, and detailed technical update procedure have not been disclosed.
The verifiable mitigation is to use an up-to-date version of the Connective signing extension and its associated host software containing the fix, while avoiding older installations. Organizations and administrators should also check deployments on users’ computers.
No specific indicators of compromise or additional workarounds have been provided. Nitro Software Belgium had not immediately responded to Dark Reading’s request for comment.
Sources
This article is an original reworking based on the sources below.
