Ironically, one of the "big reasons" allegedly behind the fork away from wayland into mir was specifically the security of input-handling. https://lwn.net/Articles/541124/rss This complaint was later debunked (since Daniel Stone of X.org fame -- who comments as daniels in the link above -- had already upgraded the wayland input-mechanisms), although too late to halt the fork.
Criticism of input-subsystem-security comes full circle