According to researchers, a critical vulnerability has been found in the iTerm macOS terminal app , an open-source application that replaces the built-in terminal app on Mac devices. This vulnerability has been known for 7 years. It has been named CVE-2019-9535 . It was discovered by the Mozilla Open Source Support Program in one of its audits.
The iTerm 2 app processes a large amount of data, which is not protected. In addition, it is used by many developers. It is a very popular application. Given the large amount of information it manages and the importance of this information (it is very confidential data), the detection of any vulnerability is of utmost importance.
According to a Mozilla blog post, the issue is very important. It is an RCE vulnerability in the tmux integration. Malicious hackers could exploit the vulnerability to execute various commands.

What can hackers do ?
Hackers could use the vulnerability for any malicious activity. For example, they could connect the terminal app to the malicious server or use the tail-f feature to watch a file with malicious data and connect it to the app. In addition, they could connect the app to a malicious site.
Typically, this vulnerability requires some trickery to be exploited by hackers. However, according to researchers, the iTerm vulnerability can be exploited much more easily. All versions of iTerm up to 3.3.5 are vulnerable to the bug. The team behind iTerm fixed the problem in the new version 2.3.6. Experts recommend that all users of the app install the updated version in order to be protected from the vulnerability. Users have the option to download the update themselves or update the software using the installed applications menu.
