
cat readme.txt That simple command in iTerm2 triggered local code execution on macOS systems. The vulnerability, dubbed MAD Bugs (CVE-2026-41253), stems from a trust failure: iTerm2 treats untrusted terminal output as valid SSH conductor protocol messages. An attacker crafts a malicious file that, when displayed, forges a DCS 2000p hook sequence to simulate announcing a conductor session. It then sends forged OSC 135 replies mimicking protocol handshakes: begin <id>, end <id> <status> r, and unhook. iTerm2 responds by issuing getshell() and pythonversion() requests; the forged replies push its state machine forward. With the session established, iTerm2 builds a run command embedding a base64-encoded payload and pipes it to the PTY. No actual SSH conductor runs - the local shell ingests those base64 chunks directly as input. The payload's final 128-byte chunk reads ace/c+aliFIo: decodes cleanly as base64 while doubling as an executable relative path. Attackers can shape the sshargs in the initial hook, embedding them into the run command's base64 for targeted control. Reported March 30, 2026, and fixed the next day in commit a9e745993c. Public disclosure came April 17, 2026. Found by an AI through an OpenAI collaboration with the MAD project. The fix had not yet landed in stable releases at disclosure. A terminal emulator tricked by its own output became the vector for shell access.
Post summary
The text announces a newly disclosed macOS vulnerability (CVE‑2026‑41253) in iTerm2, explains the exploitation method in detail, and notes that a patch was added shortly after discovery.

