ai-security EN

Security Vulnerability in a Voting System

Security Vulnerability in a Voting System

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools.

> Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary. > > Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public. > > After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the “CVR” (cast-vote record) file, containing every ballot and its selections (but not the voters’ names or other identifying information). The CVR file is available upon request, precisely because a public, ballot-level record is what makes election results independently verifiable.

Tags: voting , vulnerabilities

Posted on September 4, 2026 at 7:09 AM • 7 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.