Atiku Slams INEC Over Outdated Android 10 BVAS Ahead of 2027 Polls

The debate surrounding the integrity of Nigeria’s electoral technology has intensified following disclosures by the Independent National Electoral Commission (INEC) regarding the operating software powering the Bimodal Voter Accreditation System (BVAS).

While opposition leaders have raised red flags over the reliance on an end-of-life operating system, electoral authorities have strongly defended the platform’s security architecture, insisting that proprietary safeguards render legacy system concerns unfounded.

The controversy follows public remarks made by INEC’s Director of Information and Communication Technology (ICT), Dr. Lawrence Bayode, during an appearance on Arise TV.

Bayode confirmed that the BVAS units—first deployed during the 2021 electoral cycle —currently operate on Android version.

This revelation immediately drew sharp
criticism from the Atiku Media Office, which issued a strongly worded press release pointing out that Android 10 reached its official end of life in 2023 and no longer receives mainstream security patches or updates.

Opposition Concerns and Cybersecurity Risks

In the statement issued on Monday, the opposition camp argued that running critical national election infrastructure on an outdated operating system introduces severe cyber and operational vulnerabilities.

According to the release, the lack of ongoing security updates leaves the devices susceptible to potential exploits, where malicious actors could theoretically bypass application boundaries and gain unauthorized root access to the device file system.

“This vulnerability could allow criminal elements or hackers to bypass the BVAS application entirely, gain root access to the device file system, and potentially alter cached voter logs or polling unit result files before they are transmitted.” — Atiku Media Office.

Furthermore, the statement highlighted potential risks associated with data transmission to the INEC Result Viewing (IReV) portal over public telecommunications networks.

The opposition contended that legacy cryptographic frameworks elevate vulnerability to Manin-the-Middle (MitM) attacks, potentially enabling sophisticated actors to intercept or
manipulate data packets in transit.

Additional concerns were raised regarding biometric recognition modules and potential memory leaks that could cause application crashes during peak voting hours, echoing technical glitches witnessed in past electoral exercises.

Citing cybersecurity experts, the statement called for an independent, comprehensive code and hardware audit of all BVAS devices prior to the 2027 general elections.

INEC’s Defense: Custom Hardening and Customization

Responding directly to these apprehensions, INEC maintained that public anxiety regarding Android 10 overlooks the specialized, multi-layered security framework engineered specifically for the hardware.

Defending the commission’s position on Arise TV, Dr. Bayode explained that BVAS units were originally procured with Android 10 in 2021, and upgrading the operating system wholesale could introduce hardware compatibility issues
or compromise system performance during high-speed biometric verification.

Crucially, INEC emphasized that the electoral commission does not rely on standard consumer Android security features.

Instead, the devices run on a heavily customized, locked-down operating environment where core accreditation and result-uploading applications are strictly isolated from conventional vulnerabilities.

Contrasting these two positions reveals a fundamental divergence in risk assessment.

Regarding the operating system itself, the Atiku Media Office emphasized that Android 10 is past its end-of-life phase and lacks vendor security patches.

In response, INEC countered that the devices were procured with Android 10 in 2021, noting that wholesale operating system upgrades risk severe hardware compatibility issues and could compromise processing speed.

On the matter of security architecture, the opposition argued that legacy operating systems remain vulnerable to root access compromise, Man-in-the -Middle data interception, and malware injection.

INEC maintained, however, that standard Android components have been heavily stripped and locked down, with proprietary security layers effectively isolating core electoral applications from external threats.

Regarding mock test performance, the opposition pointed to the recent Osun State mock accreditation failures of August 1, 2026, as evidence of deep system flaws.

INEC explained that the glitches actually stemmed from legacy 2011 voter records triggering duplicate biometric flags, an anomaly that was swiftly identified and corrected.

Finally, while the opposition’s remediation call demanded an immediate, independent, and comprehensive code and hardware audit.

INEC expressed total confidence in the structural robustness of its technology, assuring the public of complete operational readiness ahead of upcoming off-cycle and general elections.

Addressing the recent mock- accreditation glitches observed in Osun State on August 1, 2026, INEC clarified that the temporary disruptions were not indicative of system failure.

According to the commission, the mock test successfully identified a technical anomaly wherein older voter registration records from 2011 produced high similarity scores in biometric matching, causing the system to flag legitimate voters.

INEC confirmed that this parameter was promptly adjusted, framing the exercise as a successful stress test rather than a systemic breakdown.

Broader Electoral Context and Legislative Stakes

The timing of the debate adds significant pressure to INEC as it approaches the Osun State gubernatorial election and prepares for the broader 2027 general elections.

Electoral observers note that public confidence remains a critical currency for the commission, particularly given the strict legal framework established by the 2026 Electoral Act.

Under Section 47(3) of the amended statute, any polling unit where a BVAS device fails and cannot be replaced immediately must have its election cancelled, triggering a mandatory rerun
within twenty-four hours if material to the final outcome.

While technical experts acknowledge that locked-down, air-gapped embedded systems can operate securely on older operating system kernels if properly hardened, the political friction highlights the immense demand for transparency in election management.

Whether INEC’s internal cryptographic and hardware assurances will satisfy political stakeholders and civil society organizations remains a central question as Nigeria counts down to the next electoral cycle.

Oluwaseun Sonde: Managing Editor, a renowned journalist with multitask functionality and a member of the Association of Corporate Online Editor (ACOE). Email: admin@mediabypassnews.com