Critical InputPlumber Flaw Enables UI Input Injection and Denial-of-Service
ID: e3436931-4f82-5e69-b174-1cf041c55028
STIX ID: report--e3436931-4f82-5e69-b174-1cf041c55028
Feed Name: GBHackers
Security researchers disclosed two critical D-Bus authorization vulnerabilities in InputPlumber (CVE-2025-66005 and CVE-2025-14338) that allow local unprivileged users to test for restricted files, leak sensitive data, cause denial-of-service, bypass Polkit authentication, escalate privileges, and inject arbitrary keystrokes by creating virtual keyboard devices; the service runs as root and affects Linux distributions including SteamOS, with fixes available in InputPlumber v0.69.0 and SteamOS 3.7.20 — administrators should update immediately and review Polkit policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
