CVE-2019-9535 describes a critical vulnerability in iTerm2 versions up to and including 3.3.5, specifically in its integration with tmux's control mode. This flaw allows an attacker to execute arbitrary commands on a victim's macOS system by injecting malicious output into the terminal. Rated 9.8 Critical (CVSSv3.1), it is a network-exploitable vulnerability requiring no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating its potential impact and the importance of patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.5CPE matchmatch criteria | cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:* | ||
>= 3.3.5, <= 3.3.5CPE match | cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.