Threat reportVulnerabilityTL-2026-1967
Origin-Validation Bypass in Connective (Nitro Software Belgium) eID Browser Extension Enables PIN Theft, Signature Forgery, and Drive-By RCE Across 2M+ Belgian Users
Origin-Validation Bypass in Connective (Nitro Software (TL-2026-1967), also tracked as Dis-Connective, is a critical-severity software vulnerability, first published 2026-08-10. It has no confirmed attribution, affects Nitro Software Belgium Connective signing browser extension (Chrome, maps to 9 MITRE ATT&CK techniques (T1005, T1036, T1056), and is covered by 9 detection rules and 13 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 9MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-1967
- Threat ID
- TL-2026-1967
- Also known as
- Dis-Connective
- Severity
- CRITICAL
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- finance, government administration
- Target regions
- belgium, Europe
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in Origin-Validation Bypass in Connective (Nitro Software
Malware and tooling: dis-connective
How Origin-Validation Bypass in Connective (Nitro Software works
Researcher James Arnott (Bay Area Labs) disclosed that the Connective signing browser extension, deployed by 8 of Belgium's 10 largest banks and 60+ government agencies, forwarded native-messaging commands to its local host binary without verifying which website issued them. Any web page could silently read unprotected eID card data, recover a user's eID PIN via a reversible token cipher, forge legally-binding eIDAS signatures, and achieve drive-by remote code execution by directing the native host to load an attacker-supplied library.
On 2026-08-10, at DEF CON, security researcher James Arnott of Bay Area Labs publicly disclosed a chain of critical design flaws in Connective, the Chrome/Firefox browser extension (Chrome Web Store ID `kclpjmhngbacampgcdojmiedamjbgjjm`) published by Nitro Software Belgium, an EU eIDAS Qualified Trust Service Provider. Connective bridges web pages to Belgium's national eID smart-card infrastructure (ISO 7816 / PKCS#11 / PKCS#15) via a native-messaging host that talks to the card reader over PC/SC. Roughly 2 million weekly active users rely on the extension, including 8 of Belgium's 10 largest banks, 60+ government agencies, and the itsme national identity layer (7.5M+ users) for services such as CSAM.be ("My Digital Keys"), Tax-on-Web, MyGov, and MyPension.
The root cause is that the extension acts as a 'thin communication layer' that relays every native-host command without validating the origin of the requesting web page; origin checking existed only as an undocumented, non-transparent client-side check rather than a real allow-list (unlike the government's own BeIDConnect extension, which hard-whitelists belgium.be/fgov.be). This let Arnott chain three exploit primitives, all demonstrated end-to-end and documented in the companion PoC repository 'dis-connective':
1. Silent card reading: any page could invoke card commands (bit-0/bit-2 feature set: GET_READERS, READ_FILE, VERIFY_PIN, COMPUTE_SIGNATURE, COMPUTE_AUTHENTICATION, SELECT_MAESTRO, GET_PROCESSING_OPTIONS, READ_RECORD) and pull the citizen's full name, birth data, National Register Number, address, photo, and all five on-card X.509 certificates — none of which are PIN-protected on the card. 2. PIN theft and signature forgery: the extension let the requesting page fully control the PIN-prompt's `entry_title`/`entry_message` text (enabling a spoofed, official-looking dialog), and the native host returned a `pinToken` to the extension that leaked both the ciphertext and its own decryption key in one 48-byte, base64-encoded blob (even-indexed bytes 0-30 = AES-128 key, bytes 32+ = ciphertext, decrypted with a hardcoded IV of `a6` repeated 16 times, AES-128-CBC). Recovering the PIN let the attacker drive further signature operations — since the eID authentication key remains active card-side until the card is removed, and the non-repudiation key needs only one fresh PIN entry per use — enabling forged, legally non-repudiable eIDAS qualified signatures. 3. Drive-by RCE: the `GET_READERS` command accepted an arbitrary `library` path (e.g. `..\..\..\..\Downloads\lib.dll`) that the native host passed straight into `LoadLibraryA()` with no validation, executing attacker-controlled code at the logged-in user's privilege level from a single page visit. Because Chrome flags raw `.dll` downloads, Arnott demonstrated bypassing that control with a polyglot file named `frien.dlly_reminder.pdf`.
Arnott's write-up also demonstrates a full CSAM.be government-portal account takeover using malicious ad-frame delivery, a single spoofed PIN dialog, and silent follow-on signing. Nitro Software Belgium was notified and shipped an incomplete origin-check fix on 2026-05-08 (~146 days after initial report); researchers found it bypassable and re-engaged on 2026-05-19; a complete fix landed 2026-06-01 (GET_READERS library-loading disabled, `pinToken` replaced with a server-side UUID reference); full origin-check enforcement was rolled out 2026-07-22. No CVE has been assigned as of disclosure. Nitro offered a $200 bug-bounty payment and did not respond to SecurityWeek's request for comment.
MITRE ATT&CK techniques used in TL-2026-1967
Collection
T1005 Data from Local System; T1056 Input Capture
Defense Evasion
T1036 Masquerading; T1574 Hijack Execution Flow
Initial Access
Execution
T1203 Exploitation for Client Execution
Credential Access
T1552 Unsecured Credentials; T1557 Adversary-in-the-Middle
Resource Development
Affected products and versions in Origin-Validation Bypass in Connective (Nitro Software
- Nitro Software Belgium — Connective signing browser extension (Chrome Web Store ID kclpjmhngbacampgcdojmiedamjbgjjm)
Vulnerable versions: all builds prior to the 2026-07-22 origin-enforcement release
Fixed in: builds released on or after 2026-07-22
Remediation for Origin-Validation Bypass in Connective (Nitro Software
Patches
- 2026-05-08: first (incomplete) fix — remote/server-side origin check added
- 2026-06-01: complete fix — GET_READERS arbitrary-library loading disabled; pinToken caching moved server-side behind a UUID reference
- 2026-07-22: full origin-check enforcement deployed
Immediate actions
- Confirm the Connective browser extension has updated to the build released after the 2026-07-22 origin-enforcement rollout; users on unpatched builds should disable/remove the extension before browsing untrusted sites
- Banks, government agencies, and itsme-integrated services should review eID-authenticated logins and electronic-signature events for accounts active before 2026-07-22 for signs of unauthorized signing or credential reuse
- Treat any eID PIN entered through a Connective-triggered dialog before the patch as potentially compromised and advise affected users accordingly
Workarounds
- Disable or remove the Connective browser extension except when actively performing an eID-authenticated transaction
- Where available, use the government-maintained BeIDConnect extension (belgium.be/fgov.be origin whitelist only) in place of Connective for government service sign-in
Longer-term hardening
- Enforce strict, server-verifiable origin allow-listing for any browser-extension-to-native-host bridge that grants access to smart-card or other cryptographic hardware, following the BeIDConnect model of whitelisting only belgium.be/fgov.be
- Redesign PIN-handling so raw PIN material and its decryption key are never returned to, or transit through, the browser extension/web-page layer
- Canonicalize and validate all file/library paths accepted by native-host commands (e.g. GET_READERS) to eliminate path traversal to attacker-controlled DLLs
- Migrate the extension off Manifest V2 and minimize the native-messaging command surface reachable from arbitrary web content
Weaknesses (CWE) in Origin-Validation Bypass in Connective (Nitro Software
Timeline of Origin-Validation Bypass in Connective (Nitro Software
- Nitro Software Belgium deploys a first, incomplete fix — a server-side remote origin check — approximately 146 days after the vulnerability was first reported to the vendor.
- Researchers determine the May 8 origin-check fix is incomplete/bypassable and re-engage Nitro Software Belgium.
- Nitro ships a complete fix: the GET_READERS arbitrary-library-loading command is disabled and pinToken handling is changed to a server-side UUID reference instead of returning the raw token to the web page.
- Full server-side origin-check enforcement is rolled out across the Connective extension, closing the remaining bypass window.
- James Arnott (Bay Area Labs) publishes the full technical write-up "8 out of 10 Banks in Belgium HATE This One Weird eID RCE" on amibeingpwned.com, alongside the dis-connective PoC repository.
- Public disclosure at DEF CON and coverage by SecurityWeek; Nitro Software Belgium offers a $200 bug-bounty payment and does not respond to SecurityWeek's request for comment; no CVE has been assigned.
Sources cited for Origin-Validation Bypass in Connective (Nitro Software
- Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
- 8 out of 10 Banks in Belgium HATE This One Weird eID RCE - Am I Being Pwned?
- GitHub - Am-I-Being-Pwned/dis-connective: Belgian eID Vulnerability Analysis & PoC
- Am I Being Pwned - free browser-extension scanner
- Am I Being Pwned - organization scanner
- GitHub - roelderickx/connective-plugin-linux: Linux replacement for the Connective Plugin
- CSAM.be - My Digital Keys (eGov profile)
- CSAM login via eID card reader (certif.iamfas.belgium.be)
- eID Belgium - official eID software
Detection coverage for TL-2026-1967
As of 2026-08-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1967 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.