CVE-2025-22275 – iTerm2 Information Disclosure

The following table lists the changes that have been made to the
CVE-2025-22275 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 03, 2025

    Action Type Old Value New Value
    Added Description iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.
    Added Reference https://iterm2.com/downloads/stable/iTerm2-3_5_11.changelog
    Added Reference https://news.ycombinator.com/item?id=42579472
Share the Post:

Related Posts