Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service
ID: 405fb7fa-328f-5229-a6b7-e29e27a85a48
STIX ID: report--405fb7fa-328f-5229-a6b7-e29e27a85a48
Feed Name: cybersecurityNews.com
Threat Score
**Critical InputPlumber vulnerabilities (CVE-2025-66005, CVE-2025-14338)** allow any local user to access a root-run D-Bus service without authentication, enabling virtual keyboard creation and keystroke injection, DoS via crafted file paths, and file-existence based information disclosure; fixes are included in InputPlumber v0.69.0 and SteamOS 3.7.20.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
