Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
A researcher disclosed serious flaws in the Connective digital identity browser extension used widely in Belgium, allowing websites to read eID and payment card data, steal eID PINs, and forge electronic signatures. The report also detailed a separate remote code execution issue, and Nitro has since fully remediated the vulnerabilities and paid a $200 bug bounty. #Connective #NitroSoftwareBelgium #JamesArnott #CSAMbe #Itsme

Keypoints

  • Connective was used by over two million users in Belgium.
  • Missing origin checks let any website communicate with the application.
  • Attackers could steal eID data, payment card details, and PINs.
  • The flaws could enable forged electronic signatures and account hijacking.
  • Nitro fixed the issues, blocked unauthorized requests, and completed security enforcement in late July.

Read More: https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/