Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

    August 10, 2026

    APOD: 2026 August 10 – Three Galaxy Pairs

    August 10, 2026

    Redmi K100 Pro, Galaxy S27, Pixel 11 specs leak, Week 32 in review

    August 10, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
    Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
    Cybersecurity

    Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

    The Tech GuyBy The Tech GuyAugust 10, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    DEF CON — A security researcher has revealed severe, now-resolved security vulnerabilities in the Connective digital identity system, a browser extension used by over two million users in Belgium. 

    Advertisement

    Developed by Nitro Software Belgium, the software is used by eight of Belgium’s ten largest banks and over 60 government agencies to manage digital identity authentication and execute legally binding electronic signatures.

    James Arnott, security researcher and founder of cybersecurity firm Bay Area Labs, discovered that the software failed to verify which website was attempting to communicate with the user’s computer. Because these checks were missing, any website or embedded online ad could interact directly with the Connective application running on a victim’s machine without their knowledge or permission.

    According to Arnott, a malicious website could silently read connected electronic ID (eID) and payment card details. Furthermore, attackers could trick users into revealing their eID PIN by triggering official-looking authentication pop-ups. Because the software allowed web pages to customize the text inside these dialog boxes without displaying the domain making the request, users had no way to verify whether a prompt was legitimate or a phishing attempt.

    When a user entered their PIN into a prompt, the application transmitted it back to the requesting webpage. An attacker could then use the PIN to generate unauthorized approval tokens to forge legally binding electronic signatures whenever the victim’s physical eID card was inserted into a card reader.

    The compromise of the eID system severely impacted the trust model of Belgium’s broader digital ecosystem, including government portals like CSAM.be and third-party identity providers like Itsme. 

    Advertisement. Scroll to continue reading.

    While these service providers contained no flaws of their own, their reliance on eID signatures meant that an attacker with stolen signing capabilities could register or hijack digital identity accounts.

    In addition to identity theft, the researcher uncovered a remote code execution vulnerability that operated independently of whether an eID card was plugged in. By exploiting a flaw in how the application processed files on the local computer, a malicious website could force the software to execute attacker-controlled code at the user level.

    An attacker could execute this drive-by attack by tricking a user into downloading a file disguised as a standard document and visiting a webpage. Requiring no special permissions, the flaw also carried the risk of spreading like a self-propagating worm by hijacking user credentials to send malicious links to other potential victims.

    Nitro fully remediated the issues 146 days after the initial report and awarded a $200 bug bounty. The company deployed updates to block unauthorized origin requests and secure PIN handling, with final security enforcement completed in late July. No CVEs appear to have been assigned.

    Nitro has not responded to SecurityWeek’s request for comment. 

    Arnott publicly disclosed the findings at DEF CON and released a blog post with additional technical details. 

    Related: Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

    Related: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

    Related: Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Critical Vulnerabilities Patched With Chrome 151 Update

    August 9, 2026

    3.8 Million Impacted by Unlimited Technology Systems Data Breach

    August 8, 2026

    Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

    August 8, 2026

    Microsoft, Apple Release Fresh Security Updates

    August 8, 2026

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)

    August 8, 2026

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    August 7, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

    August 10, 2026

    APOD: 2026 August 10 – Three Galaxy Pairs

    August 10, 2026

    Redmi K100 Pro, Galaxy S27, Pixel 11 specs leak, Week 32 in review

    August 10, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.