Logitech's macOS users experienced widespread issues with their accessories after an expired developer certificate caused the Logi Options+ and G Hub applications to stop functioning. The malfunction led to loss of custom settings, non-responsive mapped buttons, and broken custom gestures, forcing devices to revert to default configurations. Users attempting to fix the problem by reinstalling the software encountered persistent failures, as the expired certificate prevented the apps from launching and also disabled the in-app updater.
Logitech confirmed that the expired certificate, which secures inter-process communications, was the root cause and clarified that the issue was unrelated to internet connectivity. The company released manual patches for both affected applications, requiring users to download and install the updates themselves since the automated update mechanism was also impacted. Logitech publicly apologized for the disruption and acknowledged the mistake, urging users to manually update their software to restore full functionality to their devices.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Following user frustration over delayed status updates and support issues, Logitech said it would improve its communication and internal procedures to prevent similar incidents. The company also clarified the problem was not a security breach but a certificate expiration issue.
Logitech acknowledged the certificate-management mistake, apologized to users, and published manual downloads to fix the affected macOS apps. Because the expired certificate also broke the built-in updater, users had to install the patches manually.
On Monday, Logitech's expired developer/security certificate caused its macOS Logi Options+ and G HUB applications to stop launching. The failure disrupted accessory functionality for some users and reverted custom device settings to defaults.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.