A security researcher unveiled serious vulnerabilities in the Connective digital identity system used by over two million users in Belgium, including major banks and government agencies. The flaws allowed malicious websites to interact with the application without user consent, potentially exposing eID and payment card details and enabling phishing attacks for PINs. An attacker could generate unauthorized approval tokens for electronic signatures using compromised PINs.
Additional vulnerabilities enabled remote code execution on user systems. The issues were resolved by Nitro Software Belgium 146 days post-report, with updates deployed to enhance security and a $200 bug bounty awarded. The findings were disclosed at DEF CON.