Critical vulnerabilities in Nitro Software Belgium’s Connective Signing Extension exposed more than 2 million Belgian users to identity and system compromise. The browser-based eID software, used by eight of Belgium’s ten largest banks and more than 60 government agencies, failed to properly validate the origin of website requests, allowing malicious sites, ads, or hidden iframes to access eID and payment card data, replay request tokens, and present spoofed native-looking prompts to steal victims’ eID PINs. Researchers said the flaws could also be abused to submit unauthorized, legally binding electronic signature requests when a victim’s eID card was inserted, creating downstream risk for Belgium’s wider digital identity ecosystem, including services such as CSAM.be and Itsme.
A separate flaw enabled drive-by remote code execution on Windows by letting the local native host load attacker-controlled code from a web-supplied path, even without an eID card connected. Researcher James Arnott disclosed the issues after Nitro remediated them in stages, including disabling unsafe library loading, enforcing origin checks, and changing PIN-token handling; final security enforcement was completed 146 days after the initial report. Nitro, an EU-listed Qualified Trust Service Provider, reportedly paid a $200 bug bounty, and no CVE identifiers had been assigned at the time of disclosure.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Nitro finished the final security enforcement for the Connective vulnerabilities in late July, concluding remediation 146 days after the initial report. At the time of reporting, no CVEs had been assigned.
Nitro Software Belgium released a first partial fix for the Connective flaws on 8 May 2026, adding origin verification through a remote server. The update did not yet address the DLL-loading remote code execution issue or the pinToken exposure.
Arnott publicly disclosed the Connective findings at DEF CON and in a technical blog post, revealing the impact of the flaws on Belgium's digital identity ecosystem. The disclosure followed Nitro's remediation work.
After receiving the initial report, Nitro Software Belgium rolled out staged fixes including enforcing origin checks, changing PIN-token handling, and disabling risky library loading in the native host. The company also awarded Arnott a $200 bug bounty.
Researcher James Arnott identified multiple vulnerabilities in Nitro Software Belgium's Connective digital identity system, including missing origin validation that exposed eID and payment card data, PIN phishing and signing abuse, as well as a separate drive-by remote code execution issue. The software was widely used across Belgian banks and government services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcecyberveille.ch
Open sourceamibeingpwned.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.