Belgium's eID Authentication Opens Citizen Accounts to RCE
A critical vulnerability was discovered in Belgium's eID authentication system due to a severely flawed browser extension, "Connective." This vulnerability allowed attackers to steal Belgian citizens' identities, payment card information, and even execute code on victims' computers. The issue stemmed from the extension's inability to verify the websites it was connecting to, leading to a chain of exploits that could compromise sensitive accounts, including access to banking and government services. A separate RCE vulnerability within the native host application further exacerbated the risk.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
