From 0cae1f98c265c81b457a8fcd83e2fc3398da5995 Mon Sep 17 00:00:00 2001 From: zvecr Date: Thu, 26 Jun 2025 07:33:00 +0100 Subject: [PATCH 1/3] Prevent VIA keylogger --- builddefs/common_features.mk | 3 +++ quantum/via.c | 8 ++++++++ 2 files changed, 11 insertions(+) diff --git a/builddefs/common_features.mk b/builddefs/common_features.mk index 90231c9a96..c122afcff9 100644 --- a/builddefs/common_features.mk +++ b/builddefs/common_features.mk @@ -635,6 +635,9 @@ ifeq ($(strip $(VIA_ENABLE)), yes) RAW_ENABLE := yes BOOTMAGIC_ENABLE := yes TRI_LAYER_ENABLE := yes + ifeq ($(strip $(VIA_INSECURE)), yes) + OPT_DEFS += -DVIA_INSECURE + endif endif ifeq ($(strip $(RAW_ENABLE)), yes) diff --git a/quantum/via.c b/quantum/via.c index 3682b4ab2b..9446811af6 100644 --- a/quantum/via.c +++ b/quantum/via.c @@ -22,6 +22,10 @@ # error "DYNAMIC_KEYMAP_ENABLE is not enabled" #endif +#ifdef VIA_INSECURE +# pragma message "VIA_INSECURE is enabled - firmware is susceptible to keyloggers" +#endif + #include "via.h" #include "raw_hid.h" @@ -318,7 +322,11 @@ void raw_hid_receive(uint8_t *data, uint8_t length) { uint8_t rows = 28 / ((MATRIX_COLS + 7) / 8); uint8_t i = 2; for (uint8_t row = 0; row < rows && row + offset < MATRIX_ROWS; row++) { +#ifdef VIA_INSECURE matrix_row_t value = matrix_get_row(row + offset); +#else + matrix_row_t value = 0; +#endif #if (MATRIX_COLS > 24) command_data[i++] = (value >> 24) & 0xFF; #endif From eba70556f44218ca7c0ed77e76b927ba0b4bc652 Mon Sep 17 00:00:00 2001 From: Nick Brassel Date: Fri, 27 Jun 2025 23:50:09 +1000 Subject: [PATCH 2/3] Changelog stub. --- docs/ChangeLog/20250831/PR25414.md | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 docs/ChangeLog/20250831/PR25414.md diff --git a/docs/ChangeLog/20250831/PR25414.md b/docs/ChangeLog/20250831/PR25414.md new file mode 100644 index 0000000000..7ff29149ef --- /dev/null +++ b/docs/ChangeLog/20250831/PR25414.md @@ -0,0 +1,5 @@ +# Mitigate VIA keylogger security issues [#25414](https://github.com/qmk/qmk_firmware/pull/25414) + +VIA's keyboard matrix testing functionality, which allows users to identify active key presses, has been identified as a potential security concern by community members and security researchers. This feature has been demonstrated to enable unauthorized keystroke capture, with documented examples showing how malicious scripts could exploit this capability to create keyloggers. A recent security assessment revealed that user credentials could be compromised through by exploiting the matrix testing function combined with VIA's keycode assignment queries. In this attack scenario, a script could remain active during a locked session and capture password input when users authenticate upon return. + +The QMK team notified the VIA team of this security vulnerability on May 17, 2022, and made multiple subsequent attempts to coordinate a mitigation strategy. Despite repeated outreach, the VIA team has provided no acknowledgment or response to these security concerns. Given the severity of the potential security implications and the lack of engagement from the VIA team, the QMK team has unilaterally implemented a security enhancement that modifies the keyboard matrix testing functionality to prevent the reporting of key press events. This change prioritizes user security and data protection over potential feature compatibility concerns within VIA. From 304ed9b72ba30c6a754ba1e506b318a82de77c71 Mon Sep 17 00:00:00 2001 From: Nick Brassel Date: Fri, 27 Jun 2025 23:55:26 +1000 Subject: [PATCH 3/3] I accidentally a word. --- docs/ChangeLog/20250831/PR25414.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/ChangeLog/20250831/PR25414.md b/docs/ChangeLog/20250831/PR25414.md index 7ff29149ef..bee901c6ca 100644 --- a/docs/ChangeLog/20250831/PR25414.md +++ b/docs/ChangeLog/20250831/PR25414.md @@ -1,5 +1,5 @@ # Mitigate VIA keylogger security issues [#25414](https://github.com/qmk/qmk_firmware/pull/25414) -VIA's keyboard matrix testing functionality, which allows users to identify active key presses, has been identified as a potential security concern by community members and security researchers. This feature has been demonstrated to enable unauthorized keystroke capture, with documented examples showing how malicious scripts could exploit this capability to create keyloggers. A recent security assessment revealed that user credentials could be compromised through by exploiting the matrix testing function combined with VIA's keycode assignment queries. In this attack scenario, a script could remain active during a locked session and capture password input when users authenticate upon return. +VIA's keyboard matrix testing functionality, which allows users to identify active key presses, has been identified as a potential security concern by community members and security researchers. This feature has been demonstrated to enable unauthorized keystroke capture, with documented examples showing how malicious scripts could exploit this capability to create keyloggers. A recent security assessment revealed that user credentials could be compromised by exploiting the matrix testing function combined with VIA's keycode assignment queries. In this attack scenario, a script could remain active during a locked session and capture password input when users authenticate upon return. The QMK team notified the VIA team of this security vulnerability on May 17, 2022, and made multiple subsequent attempts to coordinate a mitigation strategy. Despite repeated outreach, the VIA team has provided no acknowledgment or response to these security concerns. Given the severity of the potential security implications and the lack of engagement from the VIA team, the QMK team has unilaterally implemented a security enhancement that modifies the keyboard matrix testing functionality to prevent the reporting of key press events. This change prioritizes user security and data protection over potential feature compatibility concerns within VIA.