Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service

Critical vulnerabilities in InputPlumber, a Linux input device utility used in SteamOS, could allow attackers to inject UI inputs and cause denial-of-service conditions on affected systems. The SUSE researchers tracked as CVE-2025-66005 and CVE-2025-14338, which affect InputPlumber versions before v0.69.0 and stem from inadequate D-Bus authorization mechanisms. InputPlumber combines Linux input devices into virtual input devices and runs […]

The post Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: