HomeSecurityiTerm macOS Terminal: Found with 7-year-old critical vulnerability

iTerm macOS Terminal: Found with 7-year-old critical vulnerability

According to researchers, a critical vulnerability has been found in the iTerm macOS terminal app , an open-source application that replaces the built-in terminal app on Mac devices. This vulnerability has been known for 7 years. It has been named CVE-2019-9535 . It was discovered by the Mozilla Open Source Support Program in one of its audits.iTerm

The iTerm 2 app processes a large amount of data, which is not protected. In addition, it is used by many developers. It is a very popular application. Given the large amount of information it manages and the importance of this information (it is very confidential data), the detection of any vulnerability is of utmost importance.

According to a Mozilla blog post, the issue is very important. It is an RCE vulnerability in the tmux integration. Malicious hackers could exploit the vulnerability to execute various commands.

iTerm macOS Terminal: Found with 7-year-old critical vulnerability

What can hackers do ?

Hackers could use the vulnerability for any malicious activity. For example, they could connect the terminal app to the malicious server or use the tail-f feature to watch a file with malicious data and connect it to the app. In addition, they could connect the app to a malicious site.

Typically, this vulnerability requires some trickery to be exploited by hackers. However, according to researchers, the iTerm vulnerability can be exploited much more easily. All versions of iTerm up to 3.3.5 are vulnerable to the bug. The team behind iTerm fixed the problem in the new version 2.3.6. Experts recommend that all users of the app install the updated version in order to be protected from the vulnerability. Users have the option to download the update themselves or update the software using the installed applications menu.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS