Belgium eID Software Flaws Exposed 2 Million Users to Identity Theft
Vulnerabilities in the Connective browser extension allowed for remote code execution and the theft of citizen identities.
Security researcher James Arnott has uncovered critical vulnerabilities in the software powering Belgium's electronic ID (eID) authentication system. The flaws exposed millions of citizens to identity theft and remote system compromise before being patched on July 22.
The vulnerabilities resided in the 'Connective' browser extension and its accompanying native host software, both developed by Nitro Software Belgium. These flaws allowed attackers to intercept PIN codes, steal citizen identities, and execute remote code (RCE) on users' machines. The scale of the exposure was significant, affecting a system utilized by more than 2 million individuals, over 60 government agencies, and eight of the ten largest banks in Belgium.
The Architecture of Trust
Belgium's eID system is designed as a high-security bridge between physical hardware and digital services. To authenticate, a user must possess a physical smart card and a USB card reader. The native host software and browser extension act as the intermediary, ensuring that only a person in physical possession of the ID card can access sensitive banking and government accounts. This multi-layered approach is intended to prevent remote unauthorized access by requiring a physical token.
Systemic Implications
This compromise undermines the fundamental security assumptions of Belgium's digital infrastructure. Because the eID is frequently used to register or reset other digital identities, such as the 'itsme' platform, a successful exploit could grant an attacker persistent access to a citizen's entire digital existence. James Arnott, founder of Bay Area Labs, noted that similar vulnerabilities in other extensions could leave militaries, judiciaries, and hospitals vulnerable to drive-by RCE attacks. Gal Weizman, a researcher at Rebora, added that "browser extensions are unsafe by nature."
Remediation and Response
The vulnerabilities were fully remediated on July 22. However, the timeline of the fix has raised questions regarding the responsiveness of the vendor. Arnott reported the issues 146 days before the full remediation was implemented. For his discovery and reporting of these critical flaws, the researcher received a bug bounty of $200.
While the specific Connective flaws are now patched, the incident highlights a broader risk in the reliance on browser-based extensions for critical national infrastructure. Users are encouraged to ensure their software is updated to the latest version to mitigate the risk of identity theft.