
Recently, a vulnerability was discovered in text editors that come pre-installed on Linux. This vulnerability allows hackers to take control of victim users' computers when they open a malicious text file.
Apple's latest version of macOS still uses a vulnerable version. However, attacks only occur when users have a feature called modelines enabled or enabled (themselves).
The Vim and NeoVim text editors have this vulnerability in the modelines function. This function offers some customization capabilities for a text file, such as setting specific dimensions. In fact, modelines executes commands inside a sandbox, which is isolated from the operating system. However, the vulnerability works in such a way that this protection is bypassed.
When there is no protection, the vulnerability opens a reverse shell on the computer running Vim or NeoVim. From there, hackers can issue commands to the victim's machine.
This vulnerability requires the modelines feature to be enabled, as mentioned above. On many Linux distributions, this feature is enabled by default. The vulnerability has been identified in Vim versions prior to 8.1.1365 and Neovim versions prior to 0.3.6 .
Officials have already started creating patches to address the vulnerability. users Linux should definitely install the updated version, especially if they use any of the affected versions of these word processors.
As mentioned earlier, Apple's macOS still provides a vulnerable version of Vim. In macOS, the modelines feature is not enabled by default. However, if a user enables it, they are certainly at risk, as the vulnerability can easily be exploited by a hacker and give them the ability to infiltrate the user's system.
