A critical security flaw in the browser extension used by Belgium's eID system has been discovered, exposing millions of citizens to potential identity theft and unauthorized access to sensitive accounts. The 'Connective' signing extension, developed by Nitro Software Belgium, is widely used across government and financial institutions in Belgium. However, it has been found to have serious vulnerabilities that allow attackers to perform remote code execution, steal personal information, and hijack payment card data. These vulnerabilities were publicly disclosed at DEF CON 34 by James Arnott, founder of Bay Area Labs, who highlighted that until recently, hackers could exploit these flaws with relative ease.

The problem lies in the extension's inability to verify the source of activation tokens, allowing malicious actors to adopt tokens and interact with victims' eID systems. This issue, coupled with the flawed handling of PIN codes, makes it alarmingly easy for attackers to impersonate legitimate users. Despite the widespread use of the Connective extension, its security has been heavily criticized by users, reflected in its low ratings and negative reviews on the Chrome Web Store.

The discovery of these vulnerabilities raises significant concerns about the security of browser extensions, which are inherently risky due to the extensive permissions they require. Researchers recommend that extensions should not trust messages from web pages unless they own the page to prevent cross-page exploits. While Nitro Software Belgium has patched these vulnerabilities and claims no evidence of exploitation, the incident underscores the need for rigorous security measures. Organizations dependent on such extensions are advised to limit their exposure by configuring extension settings to whitelist trusted sites.