Lucky Obukohwo, Reporting
Presidential candidate of the African Democratic Congress (ADC), Atiku Abubakar, has raised concerns over the use of what he described as an “outdated” operating system on the Bimodal Voter Accreditation System (BVAS) ahead of the 2027 general election.
Atiku, in a statement issued by his media office, said the mock accreditation failures recorded during the August 1 Osun governorship election exercise, coupled with comments by the Independent National Electoral Commission (INEC) Director of ICT, Lawrence Bayode, had exposed vulnerabilities in the electoral technology.
Truth Live News Media reports that Bayode reportedly said that during an Arise TV programme.
He said that BVAS, which was introduced into Nigeria’s electoral process in 2021, currently runs on Android version 10.
Atiku said Android 10 had reached end-of-life status in 2023 and no longer receives regular security updates and patches, arguing that its use for critical election technology could create cyber and operational risks.
He questioned why INEC, despite what he described as its substantial budget, had not upgraded the BVAS software ahead of the 2027 elections or used forthcoming off-cycle elections, including the Osun governorship poll, to test an updated version.
“Why INEC with its humongous budget cannot update the BVAS software long before the 2027 general elections or even before the series of off-season elections like the Osun State governorship election during which the updated version would have been test run,” Atiku said.
The ADC candidate described INEC’s handling of the BVAS issue as suspicious and alleged that continued reliance on outdated software could undermine the integrity of future elections.
According to him, vulnerabilities in the operating system could potentially expose BVAS devices to attacks capable of compromising voter accreditation data and election result files.
He warned that criminal elements or hackers could potentially bypass the BVAS application, gain access to the device’s file system and tamper with cached voter logs or polling-unit result files before transmission.
Atiku also raised concerns about the transmission of polling-unit results to the INEC Result Viewing (IReV) portal through public telecommunications networks.
Atiku warned that outdated security and cryptographic components could leave the electoral system vulnerable to cyber threats, including attempts to intercept, disrupt or manipulate data transmitted from polling units to the result-viewing platform.
The former vice-president also raised concerns about the biometric capabilities of BVAS, which relies on fingerprint and facial recognition technologies to authenticate voters.
He argued that an outdated biometric framework could undermine the accuracy, reliability and resilience of the system, potentially creating loopholes for attempts to circumvent voter verification.
He further cautioned that software vulnerabilities, bugs and memory-related failures associated with legacy systems could cause BVAS devices to malfunction or crash, particularly under heavy usage, leading to delays, accreditation failures and disruptions at polling units.
According to Atiku, electoral technology must undergo regular upgrades, rigorous testing and independent scrutiny to ensure reliability, security and public confidence in the electoral process.
He therefore endorsed calls by cybersecurity experts for a comprehensive and independent audit of BVAS ahead of the 2027 general elections.
Atiku said the audit should cover the entire system, including the hardware, operating software, source code, biometric components, security protocols and overall architecture, arguing that any vulnerabilities identified must be addressed well before Election Day.
“Running critical national infrastructure on an end-of-life operating system creates a broad attack surface,” he said.
“To safeguard election integrity, it is vital to perform an independent, comprehensive code and hardware audit of the BVAS devices.”



