
The issue is reportedly due to a hidden keylogging code in software drivers preinstalled on the laptops to make the keyboards work.
The keylogger affects models as far back as 2012, including the EliteBook, Spectre Pro, Pavilion, ZBook and Omen.
In a security bulletin, HP said the vulnerability could lead to local loss of confidentiality.
“A potential security vulnerability has been identified with certain versions of Synaptics touchpad drivers that impacts all Synaptics OEM partners.
“A party would need administrative privileges in order to take advantage of the vulnerability. Neither Synaptics nor HP has access to customer data as a result of this issue,” it said.
It also included patches for removing the keylogger, which was said to be a “debug trace” put in place to catch errors.
Users can access the bulletin at bit.ly/2z3lGUR for a full list of affected models and the fix to be downloaded and installed.