Belgium’s Connective eID browser software had critical flaws that could steal PINs, forge digital signatures, and run code

Critical flaws in Nitro Software Belgium’s Connective digital identity software put more than 2 million people in Belgium at risk through software used by major banks and government agencies. Researcher James Arnott said missing website-origin checks let any site or ad talk to the local eID app, read eID and payment-card data, trigger fake official PIN prompts, and send entered PINs back to the requesting page; a separate remote code execution flaw could make the app run attacker-controlled files. No CVEs were assigned, and Nitro says fixes were completed in late July after 146 days.
Why it matters: People who used this software for banking, government login, or legally binding e-signatures could have been tricked into giving up their eID PIN and having signatures forged in their name. Organizations and users relying on Connective should confirm they have the patched version installed and treat past unexpected PIN prompts or suspicious downloads as possible signs of compromise.

Sources

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
Eduard Kovacs 2026.08.10 100% relevant
This article establishes a new story by publicly disclosing severe, now-patched vulnerabilities in Belgium’s widely used Connective eID system, with national-scale impact across banks and government services.
← Back to all stories