news.mlab.sh
Back to the feed
vulnerability

Belgium's eID Authentication Opens Citizen Accounts to RCE

Critical
Image: Dark Reading
Summary

A critical vulnerability was discovered in Belgium's eID authentication system due to a severely flawed browser extension, "Connective." This vulnerability allowed attackers to steal Belgian citizens' identities, payment card information, and even execute code on victims' computers. The issue stemmed from the extension's inability to verify the websites it was connecting to, leading to a chain of exploits that could compromise sensitive accounts, including access to banking and government services. A separate RCE vulnerability within the native host application further exacerbated the risk.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.