Critical Flaws in Belgian eID Software: 2 Million Users at Risk
Critical Vulnerabilities Identified in Belgian eID System Affecting Two Million Users
Discovery of Security Flaws in Connective Digital Identity Platform
A security researcher has uncovered significant security flaws in the Connective digital identity platform, a browser extension utilized by over two million individuals in Belgium. Developed by Nitro Software Belgium, the system is integrated into eight of the country’s top ten banks and more than 60 government agencies to manage digital identity authentication and facilitate legally binding electronic signatures.
Key Vulnerabilities Uncovered
James Arnott, a security researcher and founder of Bay Area Labs, identified critical weaknesses in the software’s architecture. The vulnerabilities stemmed from the absence of mechanisms to authenticate the origin of requests, allowing any website or embedded advertisement to interact directly with the Connective application running on a user’s device without explicit consent. This flaw enabled malicious actors to silently access electronic ID (eID) credentials and payment card information.
Exploitation Mechanisms
Additionally, attackers could manipulate authentication pop-ups to deceive users into revealing their eID PIN. The software permitted web pages to customize the text within these prompts without displaying the requesting domain, making it impossible for users to distinguish between legitimate and fraudulent requests. Once a PIN was entered, the application transmitted it back to the originating webpage, granting adversaries the ability to generate unauthorized approval tokens.
Impact on Digital Infrastructure
These tokens could then be used to forge legally binding electronic signatures when the victim’s physical eID card was connected to a card reader. The compromise of the eID system disrupted the trust framework underpinning Belgium’s digital infrastructure, including government portals such as CSAM.be and third-party identity providers like Itsme. While these services themselves contained no inherent flaws, their reliance on eID signatures meant that attackers with stolen signing capabilities could exploit the vulnerability to impersonate users.
Remote Code Execution Vulnerability
Beyond identity theft, Arnott discovered a remote code execution vulnerability that operated independently of eID card presence. By exploiting a flaw in how the application handled local files, a malicious website could force the software to execute arbitrary code at the user level. This could be achieved through a drive-by attack by luring users into visiting compromised sites.
Response and Resolution
Nitro Software addressed the issues 146 days after the initial report, implementing updates to block unauthorized origin requests and enhance PIN handling procedures. Final security measures were completed in late July. No Common Vulnerabilities and Exposures (CVE) identifiers were assigned for the flaws. The company has not responded to requests for further comment.
Public Disclosure and Broader Implications
Arnott disclosed the findings publicly at DEF CON and published a detailed technical analysis of the vulnerabilities. The incident highlights the risks associated with centralized digital identity systems and underscores the importance of rigorous security validation for critical infrastructure.
“This flaw enabled malicious actors to silently access electronic ID (eID) credentials and payment card information.”
