Skip to main content
  1. Home
  2. Computing
  3. News

Patch your HP laptops — the keyboard may have a keylogger installed

Add as a preferred source on Google

HP issued a patch for its Synaptics touchpad driver last month to fix a potential keylogger issue, but it may be more widely problematic than initially expected. The keylogger security researchers identified within the driver may affect hundreds of HP laptops and mobile workstations, including its recent Spectre Pro x360 models.

The fix for this problem was released at the start of November in a dry sounding fashion; the driver update was called the “Synaptics Touchpad Driver Potential, Local Loss of Confidentiality.” Although HP did designate it as something that should be acted on as soon as possible, ZwClose breaks down exactly why this issue is potentially more dangerous than HP makes it sound.

Recommended Videos

The keylogger in question was discovered hidden within HP’s keyboard driver and looked to save scan codes. Although the logging was disabled by default, it could easily be enabled by a user with administrative access. HP’s claim is that it was a debug trace that wasn’t removed — and now has been by the patch.

In the patch notes, it also goes out of its way to highlight that neither HP itself nor the touchpad developer, Synaptics, had any access to customer information:

“A potential security vulnerability has been identified with certain versions of Synaptics touchpad drivers that impacts all Synaptics OEM partners,” the update page reads. “A party would need administrative privileges in order to take advantage of the vulnerability. Neither Synaptics nor HP has access to customer data as a result of this issue.”

Such a problem could still be easily exploitable by malware or a nefarious individual with local access to the HP machine. The fact that this news arises at a time when HP stands accused of installing spyware and tracking software on to customers’ machines (as per ZeroHedge), is hardly ideal. It’s not clear where the tracker came from — be it Windows Update or HP itself — but some users have complained of it having a negative effect on system performance as well.

Although incidents like this don’t engender much trust in a company, it is important that you acquire the patched driver either directly from HP’s website or through a Windows Update. Considering hundreds of different HP laptops are said to be affected by this bug, it’s all the more likely someone would try to exploit it, so update your system as soon as possible.

This isn’t the first time HP has had trouble with keyloggers on its platform, though the most recent one was auditory.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
WhatsApp Plus is here, and you can safely ignore this subscription
WhatsApp wants a monthly fee for what other apps include by default, and that's a problem Meta can't dress up with custom icons.
WhatsApp Plus screenshots.

WhatsApp has fiercely defended its status as a free, no-nonsense online messaging app for over a decade, but a new subscription tier is muddying the waters. 

Meta is rolling out WhatsApp Plus, a paid subscription model, to a limited number of iPhone users using the latest version of the App Store. 

Read more
Google says AI is being abused at industrial scale for cyberattacks, and it just thwarted one
Hackers used AI to find a hidden software flaw and nearly launched a mass cyberattack before Google stepped in.
Computer, Electronics, Laptop

For years, security experts warned that AI would eventually give hackers a dangerous new edge. That moment has arrived.

Google's Threat Intelligence Group has published a report confirming that a criminal hacking group used an AI model to discover a zero-day vulnerability and nearly pulled off a mass cyberattack. Google says it caught and stopped the attack before the hackers could deploy the attack at scale.

Read more
You’ve heard of flip phones, but Logitech may be making a flip mouse
A foldable Logitech mouse could be the perfect companion for digital nomads
Electronics, mouse

The foldable trend has reached phones and laptops, and Logitech may be taking it to PC accessories next. According to leaked marketing images reported by WinFuture, the company is working on an ultra-portable wireless mouse that folds shut like a tiny clamshell.

Is this Logitech’s answer to Microsoft’s Arc Mouse?

Read more