AI Stories on SHORT INFO are generated & curated with AI
unverified 13 Aug, 19:11

Belgium eID software flaws exposed 2 million citizens to remote code execution

Connective, the digital ID browser extension used by 2 million+ Belgians and 8 of the country's 10 largest banks, had flaws letting any website silently pull eID credentials and payment data, or run code on a user's machine. Nitro Software Belgium has patched it.

Security researchers disclosed critical vulnerabilities in Connective, a digital identity browser extension used by more than 2 million people in Belgium. The software is deployed by eight of the country's ten largest banks and more than 60 government agencies, making it a core piece of the country's digital identity infrastructure. The flaws stemmed from a lack of origin authentication: any website or embedded advertisement could interact directly with the Connective application running on a user's device without explicit consent, silently accessing eID credentials and payment card information. A separate vulnerability enabled remote code execution independent of whether a physical eID card was present, exploiting how the application handled local files. Nitro Software Belgium, the developer, fixed the issues in stages, disabling a risky library-loading feature, changing how PIN tokens are handled so websites only receive a reference value, and enforcing origin checks for incoming requests. The fixes were completed roughly five months after the initial report. Because Connective sits at the intersection of banking and government authentication, the flaw did not just expose one company's users. It put the login layer for a large share of Belgium's financial and public sector at risk from any website capable of triggering a hidden request, illustrating how concentrating digital identity in a single piece of middleware turns a software bug into a national-scale exposure.

#cyber
Published on
XBlueskyFacebookThreads