Security Vulnerability in a Voting System
Executive Summary
A disclosed vulnerability lets an attacker recover the order of ballots cast, enabling analysis of voter behavior without accessing machines or private data. Using AI tools, the author applied the flaw to Georgia’s May 2026 primary by processing publicly available early‑voting lists and CVR files, revealing patterns in ballot selections while respecting voter anonymity.
Intelligence Metadata - Source Publisher: Schneier on Security - Published Date: 2026-09-04T11:09:35+00:00 - Category: threat-intel
Original Description: It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary. Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public. After pointing a coding agent to the original vul...
"Being right is highly overrated. Even a stopped clock is right twice a day."
— Unknown