mimile
Back to feed
This event is part of a larger story
Франция, Казахстан, Польша: кибератаки раскрыли данные сотен тысяч
Read briefing

James Arnott reveals Belgian eID extension flaws exposed 2 million users to remote code execution

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

James Arnott reveals Belgian eID extension flaws exposed 2 million users to remote code execution

Security researcher James Arnott revealed at DEF CON 34 last week that vulnerabilities in the Connective signing extension used for Belgium's eID system allowed identity theft, payment-card hijacking and remote code execution. The flaws were fixed on July 22, after the extension had been deployed by more than 60 Belgian government agencies, eight of the ten largest Belgian banks and over 2 million individual users. Nitro Software Belgium, the extension's vendor, did not respond to a request for comment.

Vulnerability Disclosure

James Arnott, founder of Bay Area Labs, revealed the findings at DEF CON 34 last week. The vulnerabilities in the Connective signing extension enabled attackers to steal Belgian citizens' identities, hijack payment cards and execute code remotely on local machines, until they were fixed on July 22. The extension currently lists more than 2 million individual users on the Chrome Web Store. Nitro Software Belgium did not immediately return a request for comment from Dark Reading.

Deployment and User Reviews

Nitro Software Belgium said in 2021 that more than 60 Belgian government agencies and departments, eight of the ten largest banks in the country and more than 1,000 enterprises used the Connective extension. Its Chrome Web Store page currently lists over 2 million individual users. User reviews average 1.7 out of 5 stars from 542 reviewers, with many describing the tool as difficult to use.

What's Next

Nitro Software Belgium has yet to issue a public response to Arnott's disclosure. Whether the July 22 fix fully mitigates the vulnerabilities and whether Belgian authorities will review the extension's security remain open questions.

1 source

James Arnott reveals Belgian eID extension flaws exposed 2 million users to remote code execution