Belgium's eID Software Exposes 2 Million to PIN Theft
TL;DR. Severe security flaws in Belgium's Connective digital identity system allowed PIN theft and remote code execution for 2 million users. - The vulnerabilities enabled any website to interact with the eID application, exposing personal data and allowing fake authentication prompts. - Attackers could generate unauthorized tokens for legally binding electronic signatures using stolen PINs, impacting government and banking services. - The flaws, present in software used by major banks and government agencies, have since been resolved following their discovery by a security researcher.
- Security vulnerabilities in Connective eID software affected 2 million users in Belgium.
- Flaws allowed websites to interact directly with the eID application without verification.
- Attackers could steal PINs and forge electronic signatures.
- Software is used by major banks and over 60 government agencies.
- Vulnerabilities have been patched following discovery by security researcher James Arnott.
Sources
- Critical Flaws Discovered in Belgian eID Software Used by 2 Million People — securityweek.com