Security Vulnerability in a Voting System
A long-standing vulnerability in a voting system scanner allows an attacker to reconstruct the order of ballots cast simply by providing a ballot-level record file. This was recently exploited using AI tools to analyze voter behavior in Georgia, highlighting the ongoing risk posed by this easily exploitable weakness.
A vulnerability exists within a voting system scanner that enables an attacker to recover the order of ballots cast. This issue has been present for nearly four years since its initial disclosure. Recently, a security researcher was able to exploit this vulnerability to analyze voter behavior during the Georgia May 2026 primary election. The researcher leveraged a coding agent and two publicly available data sources – the early-voting list for each county and the ‘CVR’ (cast-vote record) file – to achieve this. The CVR file contains every ballot and its selections, but importantly, it does not include voter names or other identifying information. The researcher was able to accomplish this without needing to compromise any voting machines, networks, or source code, demonstrating the relative ease with which this vulnerability can be exploited.