Belgium's eID Software Exposes 2 Million to PIN Theft

TL;DR. Severe security flaws in Belgium's Connective digital identity system allowed PIN theft and remote code execution for 2 million users. - The vulnerabilities enabled any website to interact with the eID application, exposing personal data and allowing fake authentication prompts. - Attackers could generate unauthorized tokens for legally binding electronic signatures using stolen PINs, impacting government and banking services. - The flaws, present in software used by major banks and government agencies, have since been resolved following their discovery by a security researcher.

Sources

Back to QLANKR News