Release notes

Synergy 3

v3.7.1 (September 26, 2026)

Security

  • CVE-2026-63409: An options message with an odd-length list from a malicious server caused an out-of-bounds read in the client.
  • CVE-2026-65832: A modifier mapping from a malicious server pointed outside the client's modifier table and caused an out-of-bounds read.
  • CVE-2026-65976: Clipboard data from a connected computer was accepted beyond the declared and configured size limits, so a peer could grow memory without bound.
  • GHSA-vxgx-6p4m-fv83: A single-byte keyboard layout message from a malicious server terminated the client with an uncaught exception.
  • CVE-2021-42072: The server did not sufficiently verify connecting clients, so an unauthorized computer on the network could connect.
  • CVE-2021-42073: A client name matching a configured computer let an attacker enter an active session, with input and clipboard access.
  • CVE-2021-42074: A race in TLS connection handling could crash the server and disconnect every computer.
  • CVE-2021-42075: File descriptors were not closed for established connections, so a remote attacker could exhaust them.
  • CVE-2021-42076: An over-long message could exhaust the server's memory.
  • Linux login screen: The login-screen agent let any local user run commands as root, so it has been removed, and Synergy 3 no longer runs on the Linux login screen.
  • Third-party components: Bundled components had published security advisories, and have been updated to clear them.

Features

  • Dark mode, which follows your operating system, with a Light, Dark or System setting.
  • Each computer is confirmed with a code shown on both screens before it can connect, and every connection is then verified in both directions.
  • The main window can be resized to give the screen layout more room, and it remembers its size between launches.

Bug fixes

Windows

  • Synergy 3 no longer runs in Windows 7 compatibility mode, so its window renders sharply on high-DPI displays.
  • A modifier key held while crossing from a client back to a Windows server is no longer left pressed on the client after it is released.
  • Shift+Space and Ctrl+Space reach a macOS client when the Korean input method is active on the Windows server.
  • Encrypted connections no longer hold a processor core at full use after a deferred write, which large clipboard transfers caused.
  • Fixed a case where an image copied on a macOS server did not paste on a Windows client.
  • Fixed a crash converting a top-down clipboard image on screen switch.
  • Fixed a one-byte buffer overwrite and an out-of-range read when looking up a loaded module.

macOS

  • Quitting from the menu bar no longer asks you to sign in again on the next launch.
  • Clicks bring a background application to the foreground on macOS 27, and windows can be dragged by their title bar.
  • Right Option, Right Command, Right Control and Right Shift arrive on a macOS client as right-hand keys rather than left-hand ones.
  • Punctuation typed on a macOS server with a Chinese or Japanese input method active arrives on clients as ASCII punctuation rather than the input method's.
  • Fixed a cause of wrong symbols on a Japanese keyboard layout with a Windows server and a macOS client, including after a reconnect.
  • Mouse movement while the cursor is on a client no longer reaches the application under the server's cursor.
  • Fixed a multi-display macOS server switching back to itself within a second or two of the cursor crossing to a client.
  • The server's cursor is no longer enlarged by shake to locate while the mouse is being used on a client.
  • Memory no longer grows for the life of the process during long sessions.
  • An event tap registration is no longer leaked each time a client connects and disconnects.
  • Fixed a crash at startup or on layout switch when an input source reports no languages.

Linux and Wayland

  • The background service starts at login on every desktop, and is registered again after a package update.
  • A failed background service install is now reported instead of going unnoticed.
  • Portal sessions are created or restored only once the desktop is unlocked and awake, so the input capture permission dialog is not shown again after lock or suspend, and the server reconnects instead of quitting when the compositor closes the session.
  • Input capture no longer asks for permission again after the display wakes from power saving.
  • The saved portal session is kept on compositors that never report the clipboard as enabled, instead of prompting for permission on every start.
  • Fixed the cursor snapping to the left edge of the client and getting stuck when the Wayland server is placed to the right of it.
  • The cursor can leave a multi-monitor Wayland server; capture barriers are placed only on the outer edge of the combined monitors.
  • The cursor returns to the matching position on a multi-monitor Wayland server rather than shifted or on another monitor.
  • The cursor no longer jumps to the center of the screen when the compositor recreates its input devices, for example when the brightness or volume popup opens.
  • Held mouse buttons are tracked on a Wayland server, so a drag no longer switches screens part way through.
  • Each hotkey on a Wayland server triggers its own action rather than the first one registered.
  • A Wayland client releases its input grab when idle, so its display can sleep or lock.
  • The numpad no longer needs NumLock re-enabling after each switch to a client from a Wayland server.
  • A Wayland client accumulates scroll steps smaller than one wheel click into whole clicks instead of dropping them.
  • Keys held from the server are released before an X11 client applies a refreshed keyboard map, so a modifier is not left stuck when the layout changes.
  • Fixed a deadlock in the X11 clipboard.
  • Fixed a "pure virtual method called" abort when a Wayland server fails to start, for example when the port is already in use.
  • Fixed a small memory leak each time the compositor closed and reopened the input session.
  • The client retries instead of crashing when the server hostname does not resolve.
  • Releasing sleep prevention before it was requested no longer logs an error.

All computers

  • Beta builds are offered the matching stable release by the update check.
  • Scroll steps smaller than one wheel click are accumulated on the server into whole clicks, so mice that report small steps scroll on clients instead of the events being dropped.
  • Fixed a possible crash when a client disconnects, or the server stops, while a clipboard transfer is in progress.
  • Fixed a possible crash after a client disconnects during clipboard or screen-switch activity.
  • Fixed a possible crash when a client is disconnected because of a malformed message or protocol error.
  • A truncated clipboard header is rejected before its format count is read.
  • Fixed the cursor jumping to the top-left corner on return to a client in relative mouse mode.
  • The client negotiates down to a server's older protocol version again and logs that it did so.

v3.7.0-beta (June 22, 2026)

Features

  • Clipboard sharing now works between computers on Wayland sessions, for both text and images, provided the latest Wayland libraries are installed.
  • Serial key activation now requires an internet connection, with offline activation still available through a challenge-and-response for offline keys.
  • Pausing now stays in effect across computer restarts, with a dimmed tray icon showing at a glance when sharing is paused.
  • Introduced a choice between the stable and beta update tracks, so you only receive notifications in the GUI for the kind of release you want.

Enhancements

  • This release is built on a major update to the Core (1.21.1-beta) which underpins the clipboard, input handling, and stability improvements throughout.
  • Connection status for each computer is now accurate and updates live, and manually adding a computer reports success or failure correctly instead of always failing.
  • The About page now shows the application version and build date, your licence details, and the number of seats your licence covers.
  • Flatpak builds now include the components needed for clipboard sharing, bringing that feature to Flatpak users on Wayland.

Bug fixes

  • Resolved an issue where the application launched to a blank, unusable screen instead of opening normally.
  • Repaired clipboard transfer between computers, which had regressed: copied content hit a "corrupted clipboard data" size mismatch on the receiving side and did not transfer.
  • Addressed installing, upgrading, or removing the package failing on Ubuntu 26.04 with "prerm/postinst maintainer script subprocess failed with exit status 1".
  • Corrected pressing start doing nothing, with no explanation, when a background sharing process was already running.
  • Restored the back and forward mouse buttons on all platforms, where they had stopped responding.
  • Stopped a held key from registering as separate press and release events, so key repeat now behaves as expected.
  • Eliminated a crash that struck when a hotkey could not be delivered to every connected computer.
  • Prevented a crash that could occur the first time the background service started on Windows.
  • Cleared a macOS error reading "failed to get permission status from os" that left the app unable to recover, by showing the permission steps again.
  • Ended the repeated input-permission prompt that appeared on almost every start on Wayland, and kept the chosen language from being reset.
  • Repaired the window opening too small on Wayland, which clipped menus and collapsed parts of the layout.
  • Halted a retry from showing "ip or hostname is required when connecting a peer" and then doing nothing when a computer's address was unknown.
  • Removed a packaging clash that blocked installation on Fedora when another installed application shipped the same identifier file.
  • Ensured correct character output on macOS when using the RIME input method, which previously produced the wrong characters.
  • Made changing the encryption key length take effect, where the security certificate had kept its previous length until cleared by hand.

Open Source

Synergy stands on the work of countless upstream open source projects, from the libraries and toolchains we build with to the platform code that lets it run on every operating system. Thank you to everyone who has contributed to any of them, whether in code, documentation, testing, or support, and to everyone who has worked on the open source Core behind this release. We could not build Synergy without you, and we are grateful to be part of the community that makes this software possible.