HP says Conexant keylogging code should not have been included on PCs, issues fix for 2016 models, says fix for 2015 models coming Friday
HP says it has a fix for a flaw that caused a number of its PC models to keep a log of each keystroke a customer was entering.
Context & Ripple Effects
The response follows researcher disclosure that the Conexant audio driver shipped on more than two dozen HP laptop models logged every keystroke into an unencrypted file — meaning the data capture was built into the machine before it ever reached the buyer. HP's statement frames the code as an inclusion error rather than an intended feature.
The split rollout matters: 2016-model owners get the fix now, while 2015-model owners wait until Friday. It is also not HP's first input-path exposure — a year earlier, [[a:872142|researchers showed popular wireless keyboards from HP and others transmitted without encryption]], making the company's peripheral-to-driver pipeline a recurring weak point.
First-order effects
- Owners of affected HP laptops have had their keystrokes written to an unprotected local file by software they never opted into; the patch for 2016 models removes it immediately, while 2015-model buyers remain exposed until Friday's release.
- Conexant's audio driver becomes a named liability for HP, forcing the vendor to publicly own code it did not write but shipped under its brand.
Second-order effects
- PC makers are pushed toward auditing preinstalled component software: the related coverage shows the same failure mode recurring at other vendors, with Huawei later patching a Microsoft-discovered PCManager bug that behaved like surveillance malware on MateBooks.
- Component suppliers like Conexant gain a new contractual reality — OEMs must verify what diagnostic or debug code ships inside drivers, because the brand-name seller absorbs the reputational damage either way.
Third-order effects
- Trust in PCs shifts from the operating system layer down to firmware and bundled drivers, the same territory where the Intel firmware-flaw disclosures later forced industry-wide patch scrambles across millions of devices.
- If the pattern holds, procurement standards and disclosure norms will treat every piece of preinstalled code — driver, utility, or management agent — as attack surface the OEM must account for, regardless of which supplier wrote it.
The trend: PC security accountability is moving upstream from the OS to the firmware, drivers, and preinstalled utilities that OEMs ship by default, with each disclosed keylogger or firmware flaw raising the audit bar for component suppliers.