CVE-2019-9535: vulnerability in iTerm2
iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command execution
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.5%
exploitation probability
2.5%top 16% of all CVEs
observed exploitation
nono source reports it
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including 3.3.5. This vulnerability may allow an attacker to execute arbitrary commands on their victim's computer by providing malicious output to the terminal. It could be exploited using command-line utilities that print attacker-controlled content.
Affected products
iTerm2 · iTerm2Related CVEs — iTerm2
In the same product, most dangerous first.