Skip to content
ThreatCluster

Critical InputPlumber Vulnerabilities Enable UI Input Injection and DoS

First seen 12 Jan 2026, 08:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Critical vulnerabilities in InputPlumber, a Linux input device utility for SteamOS, could allow attackers to inject UI inputs and cause denial-of-service conditions on affected systems. The vulnerabilities, tracked as CVE-2025-66005 and CVE-2025-14338, affect InputPlumber versions prior to v0.69.0 and are due to inadequate D-Bus authorization mechanisms.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 184d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track SuSE and CVE-2025-14338 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed