Critical flaws in Nitro Software Belgium’s Connective digital identity software put more than 2 million people in Belgium at risk through software used by major banks and government agencies. Researcher James Arnott said missing website-origin checks let any site or ad talk to the local eID app, read eID and payment-card data, trigger fake official PIN prompts, and send entered PINs back to the requesting page; a separate remote code execution flaw could make the app run attacker-controlled files. No CVEs were assigned, and Nitro says fixes were completed in late July after 146 days.
Why it matters: People who used this software for banking, government login, or legally binding e-signatures could have been tricked into giving up their eID PIN and having signatures forged in their name. Organizations and users relying on Connective should confirm they have the patched version installed and treat past unexpected PIN prompts or suspicious downloads as possible signs of compromise.
Eduard Kovacs
2026.08.10
100% relevant
This article establishes a new story by publicly disclosing severe, now-patched vulnerabilities in Belgium’s widely used Connective eID system, with national-scale impact across banks and government services.
← Back to all stories