logo

Critical InputPlumber Flaw Enables UI Input Injection and Denial-of-Service

ID: e3436931-4f82-5e69-b174-1cf041c55028

STIX ID: report--e3436931-4f82-5e69-b174-1cf041c55028

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Divya

...
...

Security researchers disclosed two critical D-Bus authorization vulnerabilities in InputPlumber (CVE-2025-66005 and CVE-2025-14338) that allow local unprivileged users to test for restricted files, leak sensitive data, cause denial-of-service, bypass Polkit authentication, escalate privileges, and inject arbitrary keystrokes by creating virtual keyboard devices; the service runs as root and affects Linux distributions including SteamOS, with fixes available in InputPlumber v0.69.0 and SteamOS 3.7.20 — administrators should update immediately and review Polkit policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.