James Arnott reveals Belgian eID extension flaws exposed 2 million users to remote code execution
This digest was compiled by AI from multiple sources — links to the originals are below.

Security researcher James Arnott revealed at DEF CON 34 last week that vulnerabilities in the Connective signing extension used for Belgium's eID system allowed identity theft, payment-card hijacking and remote code execution. The flaws were fixed on July 22, after the extension had been deployed by more than 60 Belgian government agencies, eight of the ten largest Belgian banks and over 2 million individual users. Nitro Software Belgium, the extension's vendor, did not respond to a request for comment.
Vulnerability Disclosure
James Arnott, founder of Bay Area Labs, revealed the findings at DEF CON 34 last week. The vulnerabilities in the Connective signing extension enabled attackers to steal Belgian citizens' identities, hijack payment cards and execute code remotely on local machines, until they were fixed on July 22. The extension currently lists more than 2 million individual users on the Chrome Web Store. Nitro Software Belgium did not immediately return a request for comment from Dark Reading.
Deployment and User Reviews
Nitro Software Belgium said in 2021 that more than 60 Belgian government agencies and departments, eight of the ten largest banks in the country and more than 1,000 enterprises used the Connective extension. Its Chrome Web Store page currently lists over 2 million individual users. User reviews average 1.7 out of 5 stars from 542 reviewers, with many describing the tool as difficult to use.
What's Next
Nitro Software Belgium has yet to issue a public response to Arnott's disclosure. Whether the July 22 fix fully mitigates the vulnerabilities and whether Belgian authorities will review the extension's security remain open questions.
1 source
James Arnott reveals Belgian eID extension flaws exposed 2 million users to remote code execution



