logo

Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service

ID: 405fb7fa-328f-5229-a6b7-e29e27a85a48

STIX ID: report--405fb7fa-328f-5229-a6b7-e29e27a85a48

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-12

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Critical InputPlumber vulnerabilities (CVE-2025-66005, CVE-2025-14338)** allow any local user to access a root-run D-Bus service without authentication, enabling virtual keyboard creation and keystroke injection, DoS via crafted file paths, and file-existence based information disclosure; fixes are included in InputPlumber v0.69.0 and SteamOS 3.7.20.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.