ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Security Vulnerability in a Voting System

mediumResearch exploited in the wildimportance 40
AI summary · glm-5.3-flash

A four-year-old vulnerability letting anyone recover ballot casting order was demonstrated with AI coding agents against Georgia's May 2026 primary data.

A previously disclosed vulnerability in ballot scanners used across 21 US states, including Georgia, allows recovery of the order in which ballots were cast. Nearly four years after the original disclosure, a researcher pointed AI coding agents at the vulnerability paper and used only public data — county early-voting lists and cast-vote record (CVR) files — to analyze voter behavior in Georgia's May 2026 primary. The demonstration required no access to voting machines, networks, source code, or non-public records.

  • Vulnerability enables recovery of ballot casting order, threatening ballot secrecy
  • Affects scanners deployed in 21 US states, including Georgia
  • Exploited with AI coding agents using only public early-voting lists and CVR files
  • Original disclosure is nearly four years old, yet data remains available for the technique
  • No machine, network, or source-code access was needed for the analysis
Full article163 words · extracted from schneier.com · click to collapse

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools.

Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary.

Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public.

After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the “CVR” (cast-vote record) file, containing every ballot and its selections (but not the voters’ names or other identifying information). The CVR file is available upon request, precisely because a public, ballot-level record is what makes election results independently verifiable.

Tags: voting, vulnerabilities

Posted on September 4, 2026 at 7:09 AM7 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2026/09/security-vulnerability-in-a-voting-system.html