# Origin-Validation Bypass in Connective (Nitro Software Belgium) eID Browser Extension Enables PIN Theft, Signature Forgery, and Drive-By RCE Across 2M+ Belgian Users

> Researcher James Arnott (Bay Area Labs) disclosed that the Connective signing browser extension, deployed by 8 of Belgium's 10 largest banks and 60+ government agencies, forwarded native-messaging commands to its local host binary without verifying which website issued them. Any web page could silently read unprotected eID card data, recover a user's eID PIN via a reversible token cipher, forge legally-binding eIDAS signatures, and achieve drive-by remote code execution by directing the native host to load an attacker-supplied library.

- **Published:** 2026-08-10T00:00:00Z
- **Last reviewed:** 2026-08-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1967
- **ID:** TL-2026-1967
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-08-10, at DEF CON, security researcher James Arnott of Bay Area Labs publicly disclosed a chain of critical design flaws in Connective, the Chrome/Firefox browser extension (Chrome Web Store ID `kclpjmhngbacampgcdojmiedamjbgjjm`) published by Nitro Software Belgium, an EU eIDAS Qualified Trust Service Provider. Connective bridges web pages to Belgium's national eID smart-card infrastructure (ISO 7816 / PKCS#11 / PKCS#15) via a native-messaging host that talks to the card reader over PC/SC. Roughly 2 million weekly active users rely on the extension, including 8 of Belgium's 10 largest banks, 60+ government agencies, and the itsme national identity layer (7.5M+ users) for services such as CSAM.be ("My Digital Keys"), Tax-on-Web, MyGov, and MyPension.

The root cause is that the extension acts as a 'thin communication layer' that relays every native-host command without validating the origin of the requesting web page; origin checking existed only as an undocumented, non-transparent client-side check rather than a real allow-list (unlike the government's own BeIDConnect extension, which hard-whitelists belgium.be/fgov.be). This let Arnott chain three exploit primitives, all demonstrated end-to-end and documented in the companion PoC repository 'dis-connective':

1. Silent card reading: any page could invoke card commands (bit-0/bit-2 feature set: GET_READERS, READ_FILE, VERIFY_PIN, COMPUTE_SIGNATURE, COMPUTE_AUTHENTICATION, SELECT_MAESTRO, GET_PROCESSING_OPTIONS, READ_RECORD) and pull the citizen's full name, birth data, National Register Number, address, photo, and all five on-card X.509 certificates — none of which are PIN-protected on the card.
2. PIN theft and signature forgery: the extension let the requesting page fully control the PIN-prompt's `entry_title`/`entry_message` text (enabling a spoofed, official-looking dialog), and the native host returned a `pinToken` to the extension that leaked both the ciphertext and its own decryption key in one 48-byte, base64-encoded blob (even-indexed bytes 0-30 = AES-128 key, bytes 32+ = ciphertext, decrypted with a hardcoded IV of `a6` repeated 16 times, AES-128-CBC). Recovering the PIN let the attacker drive further signature operations — since the eID authentication key remains active card-side until the card is removed, and the non-repudiation key needs only one fresh PIN entry per use — enabling forged, legally non-repudiable eIDAS qualified signatures.
3. Drive-by RCE: the `GET_READERS` command accepted an arbitrary `library` path (e.g. `..\..\..\..\Downloads\lib.dll`) that the native host passed straight into `LoadLibraryA()` with no validation, executing attacker-controlled code at the logged-in user's privilege level from a single page visit. Because Chrome flags raw `.dll` downloads, Arnott demonstrated bypassing that control with a polyglot file named `frien.dlly_reminder.pdf`.

Arnott's write-up also demonstrates a full CSAM.be government-portal account takeover using malicious ad-frame delivery, a single spoofed PIN dialog, and silent follow-on signing. Nitro Software Belgium was notified and shipped an incomplete origin-check fix on 2026-05-08 (~146 days after initial report); researchers found it bypassable and re-engaged on 2026-05-19; a complete fix landed 2026-06-01 (GET_READERS library-loading disabled, `pinToken` replaced with a server-side UUID reference); full origin-check enforcement was rolled out 2026-07-22. No CVE has been assigned as of disclosure. Nitro offered a $200 bug-bounty payment and did not respond to SecurityWeek's request for comment.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1078 Valid Accounts
- T1203 Exploitation for Client Execution
- T1574 Hijack Execution Flow
- T1036 Masquerading
- T1552 Unsecured Credentials
- T1557 Adversary-in-the-Middle
- T1056 Input Capture
- T1005 Data from Local System

## Sources

- [Critical Flaws Discovered in Belgian eID Software Used by 2 Million People](https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/)
- [8 out of 10 Banks in Belgium HATE This One Weird eID RCE - Am I Being Pwned?](https://amibeingpwned.com/blog/8-in-10-banks-in-belgium)
- [GitHub - Am-I-Being-Pwned/dis-connective: Belgian eID Vulnerability Analysis & PoC](https://github.com/Am-I-Being-Pwned/dis-connective)
- [Am I Being Pwned - free browser-extension scanner](https://amibeingpwned.com/)
- [Am I Being Pwned - organization scanner](https://amibeingpwned.com/org-scan)
- [GitHub - roelderickx/connective-plugin-linux: Linux replacement for the Connective Plugin](https://github.com/roelderickx/connective-plugin-linux)
- [CSAM.be - My Digital Keys (eGov profile)](https://www.csam.be/en/egov-profile.html)
- [CSAM login via eID card reader (certif.iamfas.belgium.be)](https://certif.iamfas.belgium.be/fasui/login/eidservice)
- [eID Belgium - official eID software](https://eid.belgium.be/en)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1967
