A security researcher has revealed now-resolved flaws in Connective, a digital identity browser extension used by more than two million people in Belgium, that could let any website forge legally binding electronic signatures.
Developed by Nitro Software Belgium, the extension manages digital identity authentication and e-signatures for eight of Belgium’s ten largest banks and more than 60 government agencies.
James Arnott of Bay Area Labs found the software never confirmed which website it was talking to. That gap let any page or embedded ad reach the running application silently, pull connected eID and payment card details, and display official-looking authentication dialogs whose wording pages could alter while hiding the requesting domain. A victim entering a PIN sent it straight to the attacking page, letting the attacker mint unauthorized approval tokens and forge e-signatures whenever the victim’s physical eID card sat in a reader.
Because service providers across Belgium’s digital ecosystem rely on eID signatures, an attacker with stolen signing capability could register or hijack identity accounts on government portals and third-party providers such as Itsme.
Arnott also uncovered a remote code execution flaw independent of the card. The drive-by scenario hinges on social engineering: the victim downloads a file that looks like a normal document, then lands on a malicious page, and the extension runs code at the user’s privilege level. With no special permissions required, the bug could also spread like a worm, using stolen credentials to forward malicious links to new targets.
The vendor shipped complete fixes 146 days after Arnott’s initial disclosure and paid out a $200 bounty. The patches cut off unapproved origin requests and hardened PIN entry, with the final enforcement rollout finishing in late July. No CVEs were assigned.
