Connective eID Extension Flaws Let Attackers Steal Belgian ID PINs and Trigger Drive-By RCE

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Critical flaws have been found in the Connective Signing Extension, a browser component used by more than 2 million people in Belgium to access electronic identity cards and Maestro payment cards.

The now-patched issues could have allowed malicious websites, ads, or hidden iframes to read card data, steal eID PINs, create fraudulent signing requests, and execute attacker-controlled code on Windows devices.

Connective’s software acts as a bridge between websites, a browser extension, and a native application installed on the user’s computer. The native component communicates with connected smart-card readers to support authentication and document signing.

This model is widely used in Belgian banking and public-sector services, including services that rely on eIDAS-qualified electronic signatures. Qualified signatures can carry the same legal effect as handwritten signatures across the European Union.

Connective eID Extension Flaws

Have I Been Pwned researchers found that the extension did not properly bind requests to the originating website. Although most commands required an activation token, the token lacked proper origin protection.

This meant a token issued to a legitimate partner site could potentially be replayed by another website. As a result, an attacker-controlled page could interact with the native host and access data from connected Belgian eID or Maestro cards without meaningful user awareness.

A more severe flaw in the PIN verification process allowed websites to display native-looking Connective PIN dialogs with attacker-controlled titles and messages, potentially impersonating trusted banking or government services and tricking users into entering their PINs.

The PIN popup looks identical to a legitimate application, but its title and message are controlled by the attacker ( source : amibeingpwned )

According to the disclosure, the resulting PIN token was sent back to the web page and was designed to be insecure. It allegedly included both encrypted PIN material and information required to decrypt it.

This could expose the user’s eID PIN to a malicious site after a single phishing event. An attacker with the PIN and access to a connected eID card could potentially perform unauthorized authentication or signing operations while the card remained available.

The flaws also included a drive-by remote code execution issue. Researchers found that a command executed on the native host could load a library from a path provided via a web request.

An attacker could combine this with a downloaded file disguised as a harmless document, then cause the Connective software to load malicious code at the current user’s privilege level. The issue did not require an eID card to be connected, making it a broader endpoint-security risk.

The impact extended beyond individual identity theft. Belgian eID workflows are used to access high-value services, and a compromised signing capability could enable account takeover attempts or fraudulent identity verification.

Researchers demonstrated an account takeover involving CSAM, while noting that impacts on other identity platforms may depend on additional controls.

Nitro Software Belgium, the company behind Connective and an EU-listed Qualified Trust Service Provider, released fixes over several stages.

The final remediation turned off the risky library-loading capability, changed PIN-token handling so websites receive only a reference value, and enforced origin checks for requests. The company completed remediation 146 days after the initial report no CVEs had been assigned at the time of reporting.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.