A recent cybersecurity vulnerability involves Belgium's eID authentication system, where a compromised browser extension allowed hackers to steal identities, payment information, and execute code remotely on users' machines. The 'Connective' signing extension, used by numerous government agencies and banks, exhibited major security flaws despite its widespread usage.
Researchers exposed critical weaknesses enabling attackers to hijack user sessions and gain access to sensitive accounts through easily replayable tokens and poorly protected PIN codes. Additionally, the extension had a remote code execution (RCE) vulnerability that permitted arbitrary DLLs to be loaded, increasing the risk of attacks. Experts highlight the inherent risks of browser extensions, implying that many organizations could be vulnerable to similar exploits.