A vulnerability disclosed nearly four years ago in certain voting scanners continues to pose a risk to ballot secrecy, according to new research. The flaw allows anyone with access to two public data sources — the early-voting list for each county and the cast-vote record (CVR) file — to reconstruct the order in which ballots were cast, potentially linking individual voters to their choices.
In a recent demonstration, a researcher used a coding agent to exploit the vulnerability after feeding it the original vulnerability paper and the two data sources. The CVR file, which contains every ballot and its selections but not voter names, is available upon request as part of the public-record transparency that allows independent verification of election results.
“Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public,” the researcher wrote. They were able to analyze voter behavior in Georgia, one of the states using the affected scanners.
The demonstration highlights that the vulnerability remains exploitable years after its initial disclosure, now made easier with AI tools that can automate the reconstruction process. The researcher emphasized that no hacking or tampering was required — the exploit relies entirely on publicly available information.