Belgium's eID Authentication Opens Citizen Accounts to RCE

Critical vulnerabilities in a key browser extension fully compromised Belgium's eID authentication framework, allowing remote code execution on citizen accounts and exposing wider security issues with browser extensions.

Belgium's electronic ID system trust framework was fully compromised by severe vulnerabilities in a key browser extension, exposing citizen accounts to remote code execution (RCE). The flaws allowed attackers to bypass authentication and gain full control over users' systems. This incident highlights broader security risks inherent in browser extensions, which can undermine even robust national identity frameworks.