# Belgium's Digital ID System Was an Open Window for Two Million Users


When governments and banks hand browser extensions the keys to legally binding identity infrastructure, someone is eventually going to try the door. In Belgium's case, the door was not just unlocked — it had no frame.


Security researcher James Arnott disclosed at DEF CON this weekend that Connective, a browser extension built by Nitro Software Belgium and used by more than two million Belgians to authenticate with government portals and sign legal documents, contained multiple severe vulnerabilities. The software sits at the heart of Belgium's digital identity stack: eight of the country's ten largest banks use it, along with over 60 government agencies. That reach is precisely what made the flaws catastrophic rather than merely serious.


## Any Website. Any Ad. Full Access.


The foundational mistake in Connective was an absence of origin verification. The extension never checked which website was trying to talk to it. That single omission meant that any page a user visited — including a site they'd never heard of that was running a third-party advertising script — could silently open a connection to the Connective application on that user's machine.


From that foothold, an attacker could read connected eID card and payment card details without any user interaction. The card just had to be in the reader.


The attack surface expanded further through the PIN dialog mechanism. Because the software allowed websites to customize the text inside authentication prompts without displaying the originating domain, attackers could render a convincing official-looking popup demanding the user's PIN. When the user complied — reasonably trusting what appeared to be a government or banking authentication flow — the PIN was transmitted directly to the requesting webpage.


With a stolen PIN and a victim whose physical card was inserted into a reader, an attacker could generate approval tokens and forge legally binding electronic signatures in the victim's name. Not simulated signatures. Legally binding ones.


## The Cascade


This is where the story gets materially worse. Belgium's digital identity ecosystem is structured such that several services — government identity portal CSAM.be, third-party provider Itsme — rely on eID signatures as a trust anchor. Arnott confirmed those services contained no independent flaws. They didn't need any. Once an attacker could forge eID signatures, they could register or hijack accounts on any platform in that ecosystem.


This is the systemic risk of centralized digital identity: when the root trust mechanism is compromised, every service that delegates to it inherits the breach. The flaw wasn't in the banks, or in CSAM, or in Itsme. It was one layer below all of them, in a browser extension most users probably don't think about at all.


## A Drive-By That Doesn't Need the Card


Separate from the identity theft chain, Arnott discovered a remote code execution vulnerability that operated independently of whether an eID card was present. A flaw in how the application processed local files meant a malicious website could force it to execute attacker-controlled code at the user level — no elevated permissions required.


The attack path: a user downloads a file that appears to be a standard document, then visits a malicious webpage. The extension does the rest. Arnott noted the flaw also carried worm propagation potential — hijacked credentials could be used to push malicious links to the victim's contacts, spreading the attack without further attacker involvement.


A self-replicating attack chain piggybacking on nationally trusted identity software is not a theoretical concern. It's a contingency that should have been evaluated before this software touched a single government agency.


## 146 Days. $200.


Nitro remediated the vulnerabilities 146 days after the initial report, deploying updates to block unauthorized origin requests and harden PIN handling. Final security enforcement landed in late July. No CVEs appear to have been assigned to any of the flaws.


The absence of CVEs matters for reasons beyond bookkeeping. CVE assignment creates a public, searchable record that defenders, vulnerability scanners, and enterprise security teams use to triage exposure. Without them, organizations using Connective have no standard reference to check against, no automatic trigger for patch verification, and no shared vocabulary for discussing the risk internally. Nitro has not responded to press inquiries on the matter.


The bug bounty Arnott received for disclosing critical vulnerabilities in software that underpins a nation's digital identity infrastructure: $200.


That figure is not a typo. It reflects a program calibrated for minor web bugs, not for research that credibly threatened legally binding signature forgery at national scale. Researchers do this work anyway, but the signal that number sends about how seriously a vendor weighs security is not subtle.


## HackWire Analysis


The Belgian eID case is a clean example of a failure mode that appears repeatedly across digital identity infrastructure: the delegation of trust to client-side software that was never built to carry it.


Browser extensions are a notoriously difficult security surface. They sit between the browser and the operating system, often run with persistent access to local resources, and — as Connective demonstrated — can be silently invoked by any webpage if origin validation is skipped. The decision to build a national identity and legally binding signature system on top of that surface was not inherently wrong, but it demands a security posture that treats every external caller as adversarial. Connective did the opposite.


What other coverage is largely missing here: the CVE vacuum is the story that will keep mattering. When a researcher discloses at DEF CON and walks away with $200 and no CVE numbers, the practical outcome is that thousands of security teams across Belgian banks, government agencies, and third-party identity providers have no standardized way to audit whether they've patched. The fix went out — but the paper trail that enterprise security programs depend on for verification largely doesn't exist.


Broader pattern: this parallels the 2023 Okta support system breach and the 2021 Codecov supply chain attack in one important way — the most damaging entry points are increasingly the identity and tooling layers that authentic users trust implicitly. An eID extension that every Belgian has been told to install is exactly the kind of high-value, low-scrutiny target that sophisticated threat actors are looking for. The researcher who found this was acting in good faith. The next person who finds something similar may not.


For defenders in organizations using Connective, the immediate step is confirming the late July update is deployed across all endpoints. More broadly, any organization running browser extensions as part of identity or authentication workflows should be asking pointed questions about origin verification, local resource access scope, and whether their vendor's bug bounty program is scaled to the actual risk the software carries.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)