Significant vulnerabilities have been identified and addressed in the Connective Signing Extension, a widely used browser component by over 2 million Belgian users for accessing electronic identity cards and Maestro payment cards.
Potential Exploitation of User Data
The security flaws, which have now been patched, could have permitted malicious websites, advertisements, or concealed iframes to access card data, steal eID PINs, initiate fraudulent signing requests, and execute code controlled by attackers on Windows systems.
The Connective software functions as an intermediary between websites, a browser extension, and a native application on the user’s device, interfacing with smart-card readers for authentication and document signing.
Impact on Belgian Banking and Public Sector
This model is prevalent in Belgian banking and public services, including those using eIDAS-qualified electronic signatures, which are legally equivalent to handwritten signatures across the European Union.
Researchers from Have I Been Pwned identified a flaw where requests were not adequately bound to their originating websites. Although most commands necessitated an activation token, these tokens lacked sufficient origin protection.
This vulnerability allowed a token issued to a legitimate site to be reused by another site, enabling an attacker-controlled page to interact with the native host and extract data from Belgian eID or Maestro cards without significant user knowledge.
Risks of PIN Verification and Remote Code Execution
A critical flaw in the PIN verification process allowed malicious websites to display Connective PIN dialogs with attacker-controlled titles and messages, potentially deceiving users into entering their PINs under the guise of trusted services.
This could result in the exposure of a user’s eID PIN to malicious sites following a phishing attack, allowing unauthorized authentication or signing with an accessible eID card.
Additionally, a drive-by remote code execution issue was discovered, where a command executed on the native host could load a library from a path specified by a web request. This could allow attackers to execute malicious code at the user’s privilege level without requiring an eID card connection.
Response and Remediation by Nitro Software
The fallout extended beyond individual identity theft, as Belgian eID workflows are used for accessing high-value services. A compromised signing capability could facilitate account takeovers or fraudulent identity verification.
Nitro Software Belgium, the organization behind Connective, and an EU-listed Qualified Trust Service Provider, issued fixes in stages to address these vulnerabilities.
The final remediation involved disabling the risky library-loading feature, altering PIN-token handling so websites receive only a reference value, and enforcing origin checks for requests. These measures were completed 146 days post initial report, with no CVEs assigned at the time.
Stay informed on cybersecurity developments and safeguard your digital identity by integrating security solutions into your operations.
