ZeroHour
CyberScooppublished ()ingested @jeffstone500

Second flaw found in Swiss election system could change 'valid votes into nonsense,' researchers say

criticalExploit / PoC exploited in the wildimportance 60
Full article961 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

It's yet another reminder of what can go wrong when governments shift to electronic voting with no alternative plan.

Researchers have uncovered a second security flaw in the electronic voting system employed by the Swiss government.

The vulnerability involves a problem with the implementation of a cryptographic protocol used to generate decryption proofs, a weakness that could be leveraged “to change valid votes into nonsense that could not be counted,” researchers Sarah Jamie Lewis, Olivier Pereira and Vanessa Teague wrote in a paper published Monday.

This disclosure comes weeks after the same team of researchers announced they had uncovered a flaw in the e-voting system that could allow hackers to replace legitimate votes with fraudulent ones. Swiss Post, the country’s national postal service, which developed the system along with Spanish technology maker Scytl, said earlier this month that first vulnerability had been resolved.

Researchers said at the time that the vulnerability demonstrated what can go wrong when governments shift to electronic voting with no alternative plan. The security and integrity of electronic voting systems vary by country, and the vulnerabilities outlined in this research are specific to Switzerland, but other areas of the world increasingly are moving toward a voting infrastructure where it could soon be impossible to verify whether vote tampering has occurred. Christopher Krebs, head of the U.S. Cybersecurity and Infrastructure Agency told Congress last month election officials must have the ability to audit election results.

“If you don’t know what’s happening and you can’t check back at what’s happening in the system, you don’t have security,” he said.

In the paper published Monday, Lewis, Pereira and Teague said the second flaw is a weakness in the decryption proof known as the Fiat-Shamir heuristic. The vulnerability “allows a cheating authority to produce a proof of proper decryption, which passes verification, but declares something other than the true plaintext.”

Researchers, to examine the ramifications of the issue, wrote that they exhibited “an exploit in which a malicious authority … modifies selected votes during the (partial) decryption procedure and forges decryption proofs that are indistinguishable from valid ones, and would therefore pass verification.”

While such malicious activity would leave evidence “that something went wrong,” the research cited its mere possibility as evidence that the voting system does not offer “complete verifiability,” as its creators have suggested.

SwissPost has not yet confirmed the research team’s latest analysis, according to the paper.

“We are a small team of researchers investigating this code base for the first time,” they wrote. “In a few weeks, and while spending a small fraction of our time on this investigation, we have found critical breaks of both the main components of the proof that there is no server-side fraud – the complete verifiability property. We only inspected a small fraction of this voting system, and we therefore have no reason to believe that it does not contain other critical issues.”

Australia’s New South Wales Electoral Commission, which uses the same voting system, said in a statement it is not affected by the second vulnerability.

More Scoops

CASTLE ROCK, CO – JUNE 26: A dobermann wearing a service dog registration is held onstage as former Mesa County clerk Tina Peters speaks during the first day of the Rocky Mountain Voice Freedom Festival on Friday, June 26, 2026, at the Douglas County Fairgrounds in Castle Rock, Colo. (Photo by Timothy Hurst/MediaNews Group/The Denver Post via Getty Images)

Tina Peters, through attorney, backs off formal role in Shasta County elections

Peters still left the door open to working with Shasta County on elections and doubled down on her statements that electronic voting machines should be discontinued.

Norwalk, CA – June 01: A person places their Mail in ballot into a ballot box during early voting outside of the LA County Registrar-Recorder building on Monday, June 1, 2026 in Norwalk, CA. (Ronaldo Bolaños / Los Angeles Times via Getty Images)

Supreme Court approves mail-in ballots that arrive after Election Day 

DOYLESTOWN, PENNSYLVANIA – OCTOBER 29: Election equipment and supplies that will be distributed to polling locations in Bucks County are seen at a warehouse on October 29, 2024 in Doylestown, Pennsylvania. According to Deputy Director of Communications for Bucks County Jim O’Malley, county employees work with a shipping vendor over several days to move supplies and equipment in place at Bucks County’s 304 voting precincts where the supplies remain locked until accessed by poll workers on Election Day. (Photo by Hannah Beier/Getty Images)

Trump threatens executive order on elections, claims states must obey

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/swiss-voting-system-second-flaw/