Critical Flaws in Connective eID Extension Expose Belgian ID PINs, Allow RCE
Key Takeaways Critical vulnerabilities were discovered in Connective’s Signing Extension, a browser component used by over 2 million individuals in Belgium for electronic identity (eID) and...
Key Takeaways
- Critical vulnerabilities were discovered in Connective’s Signing Extension, a browser component used by over 2 million individuals in Belgium for electronic identity (eID) and payment card interactions.
- The flaws could have enabled attackers to steal eID PINs, read card data, forge signing requests, and achieve remote code execution (RCE) on Windows systems.
- The vulnerabilities posed a significant risk to Belgian banking and public-sector services, including those relying on eIDAS-qualified electronic signatures.
- Nitro Software Belgium, the vendor, has released patches to address the issues, completing remediation 146 days after the initial report.
A series of critical security vulnerabilities have been identified in the Connective Signing Extension, a widely utilized browser plugin in Belgium that facilitates interaction with electronic identity cards and Maestro payment cards. These flaws, now patched, could have exposed sensitive user data, including eID PINs, and allowed for sophisticated attack scenarios such as remote code execution.
Table Of Content
The Connective software functions as a crucial intermediary, linking websites, a browser extension, and a native application installed on a user’s computer. This native component then communicates with connected smart-card readers to enable secure authentication and digital document signing processes.
This architecture is extensively deployed across Belgium’s financial institutions and government services, particularly those that depend on eIDAS-qualified electronic signatures. These qualified signatures hold the same legal weight as traditional handwritten signatures throughout the European Union, underscoring the severity of the discovered vulnerabilities.
Connective eID Extension Flaws Uncovered
Have I Been Pwned researchers found that a fundamental security oversight existed within the extension’s request binding mechanism, specifically concerning how it verified the origin of incoming requests. While most commands required an activation token, this token lacked adequate origin protection.
This oversight meant that an activation token legitimately issued to a trusted partner website could potentially be hijacked and reused by an attacker-controlled site. Consequently, a malicious webpage could then interact directly with the native host application, gaining unauthorized access to data from connected Belgian eID or Maestro cards without the user’s explicit knowledge or consent.
A more severe vulnerability was identified within the PIN verification process itself. This flaw permitted malicious websites to generate authentic-looking Connective PIN dialogs, complete with attacker-controlled titles and messages. This capability could be exploited to impersonate legitimate banking or government services, thereby tricking users into divulging their eID PINs.
According to the vulnerability disclosure, the PIN token generated after a user entered their PIN was inherently insecure. It allegedly contained both encrypted PIN material and the necessary information to decrypt it, which was then transmitted back to the webpage.
This design could enable a malicious site to compromise a user’s eID PIN following a single successful phishing attempt. With the PIN and access to a connected eID card, an attacker could potentially execute unauthorized authentication or signing operations while the legitimate card remained physically present and available.
The discovered flaws also included a critical drive-by remote code execution (RCE) vulnerability. Researchers determined that a specific command executed by the native host application could be manipulated to load a library from a path specified in a web request.
An attacker could combine this vulnerability with a seemingly innocuous downloaded file, causing the Connective software to load and execute malicious code at the current user’s privilege level. Critically, this RCE did not require an eID card to be connected, broadening its scope as a general endpoint security risk.
The ramifications of these vulnerabilities extended far beyond individual identity theft. Belgian eID workflows are integral to accessing high-value services, and a compromised digital signing capability could lead to widespread account takeovers or fraudulent identity verification processes. Researchers successfully demonstrated an account takeover scenario involving CSAM, though they noted that impacts on other identity platforms might depend on additional security controls.
Nitro Software Belgium, the company behind Connective and a recognized EU-listed Qualified Trust Service Provider, has since rolled out a series of fixes in multiple stages. The comprehensive remediation efforts ultimately disabled the risky library-loading functionality, redesigned PIN-token handling so that websites only receive a secure reference value, and enforced robust origin checks for all requests. The company completed these remediation efforts 146 days after the initial report. No CVEs had been assigned to these vulnerabilities at the time of reporting.
What You Should Do
- Ensure your Connective Signing Extension is updated to the latest available version immediately.
- Exercise extreme caution with any prompts requesting your eID PIN, even if they appear legitimate. Always verify the authenticity of the website or service.
- Be wary of unexpected downloads or files, even if they seem harmless, as they could be part of a sophisticated attack chain.
- Regularly monitor official communications from Connective or your financial institution for further security advisories.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.