www.darkreading.com 8/13/2026, 8:52:21 AM · external

Belgium eID flaw exposes users to theft and remote code execution

Belgium eID flaw exposes users to theft and remote code execution

A recent cybersecurity vulnerability involves Belgium's eID authentication system, where a compromised browser extension allowed hackers to steal identities, payment information, and execute code remotely on users' machines. The 'Connective' signing extension, used by numerous government agencies and banks, exhibited major security flaws despite its widespread usage.

Researchers exposed critical weaknesses enabling attackers to hijack user sessions and gain access to sensitive accounts through easily replayable tokens and poorly protected PIN codes. Additionally, the extension had a remote code execution (RCE) vulnerability that permitted arbitrary DLLs to be loaded, increasing the risk of attacks. Experts highlight the inherent risks of browser extensions, implying that many organizations could be vulnerable to similar exploits.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline