BlackTree Security · Infrastructure · Automation · AI

Connective

Connective

Belgium’s Digital ID Trust Layer Was One Download Away From RCE

Belgian flag beside an eID smart card and browser-extension attack chain

Researchers found that Belgium’s widely used Connective signing extension could expose eID and Maestro card data, recover PINs and execute attacker-controlled code through its native host. The flaws were fixed in July, but the case shows how a powerful browser extension can quietly undermine an otherwise strong national identity system.