Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Politics

Researcher warns of critical flaws in India's ECINET voter platform, only one patched

A security researcher disclosed serious vulnerabilities in the Election Commission of India's voter services website and ECINET app in July; CERT-In has confirmed fixing one issue while the others remain pending.

In July, security researcher Nisarga Adhikary sent a detailed report to the Election Commission of India and the cyber-security agency CERT-In, flagging several high-risk flaws in the commission's voter-services portal and the ECINET Android application. The vulnerabilities include an open server that returns election officials' names and phone numbers without authentication, and an app that embeds encryption keys and access tokens, allowing potential interception or alteration of data on public networks.

CERT-In responded on October 6, confirming that a minor issue labeled “Client-Side Static Response Encryption (Hardcoded AES Key)” had been fixed, while work on the remaining critical bugs is ongoing. Adhikary noted that the server's lack of login or CAPTCHA could enable large-scale harvesting of officials' contact information, and the app's insecure design could let malicious actors spoof or tamper with cVIGIL incident reports.

No evidence of data theft has been reported, but the unresolved flaws raise concerns about the integrity of India's electoral infrastructure. A committee led by a senior Deputy Election Commissioner has been tasked with reviewing ECINET following these disclosures.

Why it matters

Unaddressed security gaps in India's election systems could jeopardize the confidentiality and integrity of voter and official data.

In this story

electoral securityvoter-services websiteECINET appcritical vulnerabilitiesdata exposureencryption keysCERT-In response
Get the beta ↗