Logitech Updates 'Options' Customisation App to Fix Security Flaw Allowing Keystroke Injection Attacks

Advertisement
By Jagmeet Singh | Updated: 14 December 2018 14:16 IST
Highlights
  • Logitech has released Options app version 7.00.564
  • Google's Project Zero team reported the security flaw in September
  • Logitech confirms the fix of the bug
Logitech Updates 'Options' Customisation App to Fix Security Flaw Allowing Keystroke Injection Attacks

Logitech Options app is designed to let you customise your mouse, keyboard, or touchpad

Logitech Options, the app that is designed to enable customisation of Logitech mice, keyboards, or touchpads, has now received a security patch. The patch essentially fixes a security flaw that was allowing attackers to inject arbitrary keystrokes and send system commands - all through gaining remote access. Google's Project Zero security team intimated the Logitech team about the bug back in September. However, Logitech released Options 7.00.564 on Friday to ultimately address security concerns. A Google security researcher had already detailed the flaw in a bug report, before the patch arrived, thanks to the 90 days deadline expiring.

Google security researcher Tavis Ormandy in his bug report states that the Logitech Options was opening a WebSocket server on systems on which it's installed without any origin checking process. That made the app vulnerable to keystroke injection attacks. "The only 'authentication' is that you have to provide a PID [process ID] of a process owned by your user, but you get unlimited guesses so you can bruteforce it in microseconds," explained Ormandy in the report.

"After that, you can send commands and options, configure the 'crown' to send arbitrary keystrokes, etc, etc."

Alongside raising the bug report, Ormandy personally reported the issue to the Logitech engineers in mid-September. Logitech acknowledged the flaw soon upon receiving its report. However, the company took over three months to bring its patch - more than Google Project Zero's 90-day deadline for public disclosure. It did bring an updated Options app on October 1, but that update didn't include any fixes for the reported security issues, as the security researcher wrote in a comment to his bug report on the Chromium site.

Advertisement

"This now past deadline, so making public," said Ormandy. "I would recommend disabling Logitech Options until an update is available."

Soon after the bug report became public, it gained some attention among security researchers and finally pushed Logitech to release the patch.

Advertisement

"The release of Logitech Options 7.00, which addresses Origin checks and type checking, is now live and can be downloaded for Windows and Mac," Logitech tweeted on Friday to confirm the fix.

You can download the updated Options app on your PC to start customising your Logitech mouse, keyboard, or touchpad. The app supports devices such as MX Vertical, MX Ergo, MX Anywhere 2S, K600 TV Keyboard, MK850 Performance, MK540 Advanced, and MX900 Performance Combo for customisations.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Logitech Options, Logitech
Advertisement
Popular Mobile Brands
  1. Vivo Y400 Pro 5G India Launch Today: All You Need to Know
  2. Oppo Reno 14 5G Series Teased to Launch in India Soon
  3. OTT Releases This Week: Ground Zero, Detective Sherdil, Found S2, and More
  4. Nothing Phone 3 to Get New Glyph Matrix Interface on the Rear Panel
  5. Samsung Galaxy M36 5G India Launch Date and Key Features Revealed
  6. YouTube Shorts Will Soon Let You Create AI Video Clips With Veo 3 Model
  7. Vivo T4 Lite 5G to Launch in India on June 24; Chipset Confirmed
  8. Realme Buds Air 7 Pro Review: Eye-Catching Design, Thumping Bass
  9. Samsung Galaxy S25 FE Leaked Render Suggests Improved Design
  10. Samsung Galaxy Z Fold 7 Leaked Renders Suggest Design Changes
  1. Samsung Galaxy S25 FE Renders Leak Online, Suggesting Familiar Design With Thinner Bezels
  2. Samsung Galaxy Z Flip 7 Leaked Renders Suggest Edge-to-Edge Cover Display
  3. YouTube Shorts to Bring Google’s Veo 3 Video Generation Model With Audio Support 'This Summer'
  4. Samsung Galaxy Z Fold 7 Leaked Renders Hint at Design Changes; Storage Options Tipped
  5. Vivo Y400 Pro 5G Launching Today: Price in India, Expected Features and Specifications
  6. Fast Radio Bursts Reveal Universe’s Missing Matter Hidden in Cosmic Intergalactic Fog
  7. Apollo Astronauts Found Orange Glass Beads on the Moon, Scientists Now Know Why
  8. World’s Oldest Tailored Dress Found in Egyptian Tomb Dates Back Over 5,000 Years
  9. Ancient Footprints in White Sands Confirm Humans Reached America 23,000 Years Ago
  10. Humanoid Robot Achieves Controlled Flight Using Jet Propulsion and AI Systems
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.