QInput is input infrastructure. Raw global input is sensitive even when the library itself does not persist or transmit events.
- QInput contains no network client and does not transmit input events.
- Raw input is opt-in through the raw feature mask.
- The Wayland backend does not bypass compositor security to obtain passive input.
- macOS permission failures are surfaced instead of being bypassed.
- Native event payloads contain key/button metadata and pointer coordinates, not clipboard contents or typed text.
- The library does not log individual raw input events.
Applications embedding QInput should enable the smallest raw mask they need and should never log raw event streams by default. Raw keyboard events can reveal behavioral information even though QInput exposes physical/native key codes rather than decoded text.
Treat native binaries as executable code: build them in trusted CI, sign release artifacts where the host platform supports signing, and verify the expected artifact before loading it.
Report security issues privately to the maintainer of the embedding project rather than publishing exploit details in a public issue before a fix is available.