Cybersecurity expert Oluwatobi Ayodele has raised serious concerns over the cybersecurity architecture of Nigeria’s Bimodal Voter Accreditation System (BVAS), warning that the continued use of Android 10-powered devices could expose the country’s electoral infrastructure to sophisticated cyber threats ahead of the 2027 general elections. Oluwatobi’s concerns followed revelations by the……
Cybersecurity expert Oluwatobi Ayodele has raised serious concerns over the cybersecurity architecture of Nigeria’s Bimodal Voter Accreditation System (BVAS), warning that the continued use of Android 10-powered devices could expose the country’s electoral infrastructure to sophisticated cyber threats ahead of the 2027 general elections.
Oluwatobi’s concerns followed revelations by the Independent National Electoral Commission (INEC) Director of ICT, Dr Lawrence Bayode, that BVAS devices currently operate on Android 10 and that the commission has no immediate plan to upgrade the operating system. Reports of the disclosure emerged shortly before the August 15 Osun State governorship election.
According to Oluwatobi, the disclosure should be treated as a national cybersecurity concern rather than merely a technical decision by the electoral commission.
“Recently, we have seen how AI models can break through secure sandboxes and attack external entities, demonstrating a massive leap in offensive cybersecurity capabilities. Against this backdrop of hyper-advanced, automated threats, the state of our national election infrastructure is terrifying,” he said.
“While political analysts are busy dissecting voter turnout and party strategies, I am staring at a completely different dashboard: the attack surface of the Bimodal Voter Accreditation System (BVAS).
“We are preparing to scale a national election infrastructure on top of obsolete software, underpowered hardware, and a security posture that belongs in a museum, not a Situation Room.”
Read Also: Akinboro Petitions EFCC, DSS Over NBA Election Cyber Attack Allegations
Oluwatobi noted that Android 10 was released in 2019 and argued that relying on an ageing operating system for election technology creates significant security concerns, particularly as the devices are expected to be deployed on a much larger scale during the 2027 elections.
However, publicly available Android security records show that the two specific critical vulnerabilities, CVE-2023-20951 and CVE-2023-20954, cited in Oluwatobi’s analysis were listed by Google as affecting Android 10. Both were critical remote-code-execution vulnerabilities that required no user interaction.
Oluwatobi nevertheless maintained that the broader issue remains the continued reliance on an outdated operating system for critical electoral technology.
He described INEC’s explanation that upgrading the operating system would require hardware and RAM upgrades as evidence of what he called “hardware technical debt”.
“The ICT Director stated that upgrading the operating system would require upgrading the RAM and hardware, which would ‘slow the system down’. This is a spectacular admission of hardware technical debt,” Oluwatobi said.
“It means that when INEC procured these devices in 2021, they bought hardware so underpowered and highly constrained that it had zero lifecycle scalability. They did not build a resilient technological framework for Nigerian democracy; they bought disposable tablets.”
The cybersecurity expert also rejected the argument that security controls within the BVAS application could sufficiently compensate for weaknesses in the underlying operating system.
He said: “Relying on app-level security on an unpatched Android 10 device is a catastrophic miscalculation. In the Android ecosystem, the OS kernel is the absolute authority. It dictates memory allocation, file permissions, and network routing.
“You cannot patch a sinking ship with paint.”
Oluwatobi argued that application-level security should form part of a broader defence strategy rather than serve as a substitute for maintaining the underlying operating system.
“Application security is designed to protect the app from the user; it cannot protect the app from a compromised operating system,” he said.
His warning comes as INEC prepares for the 2027 general elections, with the commission’s official timetable showing the presidential and National Assembly elections scheduled for January 16, 2027, followed by governorship and State House of Assembly elections on February 6, 2027.
The scale of the deployment is expected to be significantly larger than the one witnessed in Osun State. INEC deployed 4,427 BVAS devices for the August 15 Osun governorship election, including 664 backup units.
Oluwatobi warned that vulnerabilities or weaknesses that may appear manageable during a state election could become considerably more consequential when the same technological architecture is deployed across the country.
“If we are already seeing architectural strain and defending the use of obsolete software for a single-state election, what happens when this vulnerable fleet is deployed nationwide?” he asked.
“We are handing sophisticated political threat actors and potentially hostile state-sponsored APTs a wide-open door.”
He further questioned the cybersecurity governance and oversight mechanisms surrounding electoral technology, particularly the responsibilities of the Federal Ministry of Communications, Innovation and Digital Economy, the National Information Technology Development Agency (NITDA), the Office of the National Security Adviser (ONSA) and other relevant cybersecurity institutions.
Oluwatobi pointed to Nigeria’s 2024 Designation and Protection of Critical National Information Infrastructure Order, which established measures for identifying, securing and protecting critical information infrastructure across key sectors. The order specifically seeks to reduce incidents capable of damaging, disrupting or interfering with the operation and integrity of designated critical infrastructure.
He questioned whether electoral technology should receive a more rigorous and independently verifiable cybersecurity assessment before being deployed for a nationwide election.
“The failure belongs to a bureaucratic blind spot created by two overlapping giants: the Federal Ministry of Communications, Innovation and Digital Economy and the Office of the National Security Adviser,” he said.
Oluwatobi argued that technology procurement for critical national systems should include stronger lifecycle planning, independent security testing, threat modelling, penetration testing and continuous vulnerability management.
“We have one Ministry responsible for ensuring the technology is up to standard, and a National Security Office responsible for ensuring it cannot be hacked. Yet, between this web of mandates, councils, and executive orders, INEC is somehow allowed to deploy an unpatched, obsolete device for a national election,” he said.
He urged INEC to treat cybersecurity as a central component of electoral integrity rather than an administrative or technical afterthought.
“We cannot run a 2027 democracy on 2019 software,” Oluwatobi said.
“With the rapid evolution of AI, threat actors do not have to work hard to compromise outdated systems. If a political threat actor decides to target the BVAS fleet next year, they won’t need to invent a new cyber weapon; they will just use known vulnerabilities and weaknesses if those systems remain inadequately protected.”
Oluwatobi concluded with a stark warning to the electoral commission.
“INEC needs to stop treating cybersecurity as a secondary administrative checkbox and start treating it as the core pillar of our electoral process. The Osun election was a warning shot.
“If INEC insists on deploying unpatched, hardware-constrained devices next year, we are not preparing for an election, we are preparing for a cyber incident.”

